MCP Authorization (OAuth 2.1 for MCP)
The MCP specification's transport-level authorization flow for HTTP-based MCP servers, based on a subset of OAuth 2.1 and related RFCs.
Tags
Description
Authorization is optional; HTTP-based implementations SHOULD conform, STDIO implementations SHOULD instead read credentials from the environment. Builds on OAuth 2.1 (IETF draft), RFC 6750 bearer tokens, RFC 8414 authorization server metadata and related specs.
Agent access
Related
- Model Context Protocol (MCP): Open protocol that standardizes how AI applications connect to external tools, data sources and prompts via MCP servers.
- Auth0 for AI Agents: Auth0's identity toolkit for AI agents: user authentication, delegated authorization, human-in-the-loop (CIBA) and fine-grained authorization for RAG.
- WorkOS AuthKit for MCP: WorkOS AuthKit guide and support for securing MCP servers that require authentication.
- Stytch Connected Apps (MCP auth): Stytch Connected Apps: authorization for remote MCP servers and connected agent integrations.
Guides & comparisons
- Connect an agent to a remote MCP server (Guide): How remote MCP works over Streamable HTTP in the 2026-07-28 spec, how OAuth sign-in is discovered, and copy-paste configs for Claude Code, Codex, Cursor, Gemini CLI, VS Code and Claude connectors.
- Connect a remote MCP server (Skill): Configure, verify and troubleshoot a remote Streamable HTTP MCP server in the major agent clients, including OAuth discovery and protocol-version checks.
Sources
Machine-readable
- JSON
- Markdown
- Source file on GitHub (edit via pull request)