PropelAuth Logo

MCP AUTHENTICATION

Authentication for your MCP server

Your users are connecting Claude, ChatGPT and Cursor to your product. PropelAuth handles the login, the consent screen, the scopes and the tokens, so your MCP server only has to implement tools.

GeminiconnectedCopilot StudioconnectedWindsurfconnectedClaude CodeconnectedCursorconnectedClaudeconnectedChatGPTconnectedOpenCodeconnected

HOW IT WORKS

From a 401 to a scoped token

An OAuth 2.1 authorization server for the MCP server you build, behind the same login as the rest of your product.

AI clientClaude · Cursor · ChatGPTYour MCP servertoolsPropelAuthlogin · consent · tokenstools/callauthorizeintrospect

FEATURES

Everything the security review will ask about

Org ScopesMCP → ScopesConsent screenread:sensitive_dataOwnerAdminMemberwrite:org_configOwnerAdminMemberview:team_membersOwnerAdminMemberAcmeMemberFOR YOUR ORGANIZATIONRead sensitive dataWrite org configView team members

Org scopes, gated by role

Assign each org scope to the roles that may grant it. An Admin can hand an agent a sensitive scope, a Member sees it grayed out, and your customer's roles set the policy for AI access.

Image showing a user selecting one of our SAML guides

Enterprise SSO, already handled

When your customer's employees sign in through Okta or Entra ID, so do their AI clients. An employee deactivated there can't connect a new client or re-authenticate.

Read ResourcesRequiredRead sensitive dataAuthorizeDenyAn app calling itself “Claude Code” wantspermission to access your accountclaude-code.aiUnknown publisherYou'll return to localhost:54545, an app on your computer.Only approve if you just started this from Claude Code.Claude wants permission to access your accountclaude.aiRecognizedYou'll return to claude.ai/api/mcp/auth_callback

Consent that resists phishing

A client is identified by its domain, not the name it gives itself. Unknown publishers get a badge and no logo, and local apps get a warning that names the client and the port.

How do users create OAuth clientsClient ID Metadata DocumentDynamic Client RegistrationfallbackManually via Hosted PagesRegistrationclaude.aiclient_id/oauth/client-metadata.jsonMetadata documentIdentity document fetchedRedirect address verifiedRecognizedRecognizedNothing for you to register

Works with any AI client

Your users connect Claude, ChatGPT, Cursor or whatever ships next month, and the client registers itself. CIMD and DCR are both built in, and CIMD clients need no allowlist entry.

MCP Audit Log+ Client+ Event type+ Date+ ActorEventDescriptionWhenConsent grantedjane@acme.com granted Claude accessjust nowClient deletedGemini deleted by admin@acme.com3 hr agoClient updatedClaude Code redirect URI changed3 hr agoConsent grantedamir@acme.com granted Windsurf access3 hr agoConsent revokedraj@acme.com revoked ChatGPT access1 hr agoClient createdCursor registered with CIMD4 min ago

A dedicated MCP audit log

Every client created, updated or deleted, and every consent granted or revoked. When a security team asks who connected what, you have the answer.

Authorize requestsClauderesource=https://myserver.com/mcpaud ✓Copilot Studioresource=https://myserver.com/mcpaud ✓Default Resourcehttps://myserver.com/mcp

Legacy clients, same rules

Some clients still run plain OAuth 2.0 and never say which server a token is for. Default Resource fills in yours, so their tokens stay audience-bound.

FAQ

Frequently asked questions

What is MCP authentication?


How do I add authentication to my MCP server?


Do you support Dynamic Client Registration (DCR) and Client ID Metadata Documents (CIMD)?


Which AI clients work with MCP authentication?


Does MCP authentication work with Enterprise SSO and role-based access control?


I have less frequently asked questions...


Abstract image of clouds

TESTIMONIALS

The API documentation, the customer support and the overall experience is unparalleled.

Pujun Bhatnagar

Kintsugi, Founder

I just want to mention that the SAML feature is awesome... PropelAuth was a life saver there.

Tyler Johnson

Tennr, Founder

[PropelAuth] allowed us to focus on our main product features, while not worrying about the auth portion.

Josh Gray

Artemis, Founder

Incredibly easy set up, new features dropped all the time. [The team] has been fantastic every step of the way. I cannot recommend PropelAuth highly enough.

Stephen Campbell

Revamp, Founder

We’re using Propelauth for authentication, and it’s been fantastic. The organization, user management, and everything else is top-notch and I’m thrilled with my decision to use it.

Founder

Stealth

Auth is basically the only part of our system that isn’t always on fire as we grow.

Founder

Seed Stage Startup

Letter AI logoSalesforce logoBrilliant Earth logoAnglera logoTennr logoHubble logoKintsugi logoStably logoSafetykit logoMercoa logoMetriport logoBuildwitt logoVector logoOctomind logoClueso logoDuro logoLetter AI logoSalesforce logoBrilliant Earth logoAnglera logoTennr logoHubble logoKintsugi logoStably logoSafetykit logoMercoa logoMetriport logoBuildwitt logoVector logoOctomind logoClueso logoDuro logo
Ready
for anything

No product too complicated

Ship with confidence, knowing you’re prepared to handle any user challenge your customers bring.