Looks like you can do it in the authorized_keys file:
permitopen="host:port"
Limit local ``ssh -L'' port forwarding such that it may
only connect to the specified host and port. IPv6 addresses can
be specified with an alternative syntax: host/port. Multiple
permitopen options may be applied ...