Skip to main content
Glama
Jason-CKY

MCP Auth Example

by Jason-CKY

MCP Auth Example

This project demonstrates a FastMCP server with both authenticated and unauthenticated endpoints. Bearer token authentication is enforced at the Nginx proxy layer. Envoy acts as a reverse proxy, forwarding requests to the MCP server and integrating with Open Policy Agent (OPA) for fine-grained authorization decisions. The repository includes example clients and a Docker setup for running all components together.

Features

  • FastMCP server with and without authentication

  • Example Python clients for both endpoints

  • Docker Compose setup with Nginx, Envoy, and OPA integration

Related MCP server: AuthMCP Gateway

Project Structure

.
├── Dockerfile              # Dockerfile for MCP server
├── README.md
├── client.py               # Example client for both endpoints
├── docker-compose.yml      # Docker Compose setup (Nginx, Envoy, OPA, MCP)
├── proxy
│   ├── envoy               # Envoy config
│   │   ├── Dockerfile
│   │   ├── entrypoint.sh
│   │   └── envoy.yaml
│   ├── nginx.conf          # Nginx config for Bearer auth
│   └── policy.rego         # OPA policy for Envoy
├── pyproject.toml          # Python project config
├── server.py               # Unauthenticated MCP server (port 8000)
└── uv.lock

Quick Start

1. Install Dependencies

Install Python dependencies (requires uv):

uv sync

2. Build and Start Services

Build and start all services using Docker Compose:

docker compose up --build -d

3. Test the Clients

Unauthenticated

uv run client.py

Authenticated

Edit client.py to use the authenticated endpoint and provide a valid token.

How It Works

  • server.py: Runs a FastMCP server on port 8000 (no auth).

  • client.py: Example client for both endpoints, supports custom authentication.

  • proxy/: Contains Nginx and Envoy configs for authentication and policy enforcement.

Requirements

  • fastmcp

  • Docker & Docker Compose

  • uv (for Python dependency management)

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A secure MCP server using FastMCP and Eunomia Authorization, providing granular access control with dynamic JSON policies.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Secure MCP protocol proxy with OAuth2 + Dynamic Client Registration (DCR), JWT auth, RBAC, rate limiting, multi-server aggregation, and a monitoring/admin dashboard.
    12
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    FastMCP server with Bearer token authentication mounted on FastAPI, including OAuth 2.1 endpoints for dynamic client registration and metadata discovery.
    -
  • F
    license
    Not graded
    quality
    D
    maintenance
    A proof-of-concept MCP server implementing OAuth 2.1 authorization with CIMD client registration and PKCE, demonstrating protected resource access and step-up authentication.
    -