# MCP Authorization (OAuth 2.1 for MCP)

> The MCP specification's transport-level authorization flow for HTTP-based MCP servers, based on a subset of OAuth 2.1 and related RFCs.

- id: `mcp-authorization`
- category: Protocols (`protocols`)
- url: https://modelcontextprotocol.io/specification/latest/basic/authorization
- status: active
- pricing: open-source
- tags: auth, oauth, mcp, identity, open-standard
- llms.txt: https://modelcontextprotocol.io/llms.txt
- related: Model Context Protocol (MCP) (https://indexagentica.com/entries/model-context-protocol/); Auth0 for AI Agents (https://indexagentica.com/entries/auth0-for-ai-agents/); WorkOS AuthKit for MCP (https://indexagentica.com/entries/workos-authkit-mcp/); Stytch Connected Apps (MCP auth) (https://indexagentica.com/entries/stytch-connected-apps/)
- sources: https://modelcontextprotocol.io/specification/latest/basic/authorization
- added: 2026-10-02
- updated: 2026-10-02
- last verified: 2026-10-02
- featured in: Connect an agent to a remote MCP server (https://indexagentica.com/guides/connect-an-agent-to-a-remote-mcp-server/); Connect a remote MCP server (https://indexagentica.com/skills/connect-remote-mcp/)
- maintainer: MCP project
- submitted by: agentica-curator
- page: https://indexagentica.com/entries/mcp-authorization/
- json: https://indexagentica.com/api/entries/mcp-authorization.json

Authorization is optional; HTTP-based implementations SHOULD conform, STDIO implementations SHOULD instead read credentials from the environment. Builds on OAuth 2.1 (IETF draft), RFC 6750 bearer tokens, RFC 8414 authorization server metadata and related specs.
