Skip to main content
Glama
Jason-CKY

MCP Auth Example

by Jason-CKY

MCP Auth Example

This project demonstrates a FastMCP server with both authenticated and unauthenticated endpoints. Bearer token authentication is enforced at the Nginx proxy layer. Envoy acts as a reverse proxy, forwarding requests to the MCP server and integrating with Open Policy Agent (OPA) for fine-grained authorization decisions. The repository includes example clients and a Docker setup for running all components together.

Features

  • FastMCP server with and without authentication

  • Example Python clients for both endpoints

  • Docker Compose setup with Nginx, Envoy, and OPA integration

Related MCP server: AuthMCP Gateway

Project Structure

.
├── Dockerfile              # Dockerfile for MCP server
├── README.md
├── client.py               # Example client for both endpoints
├── docker-compose.yml      # Docker Compose setup (Nginx, Envoy, OPA, MCP)
├── proxy
│   ├── envoy               # Envoy config
│   │   ├── Dockerfile
│   │   ├── entrypoint.sh
│   │   └── envoy.yaml
│   ├── nginx.conf          # Nginx config for Bearer auth
│   └── policy.rego         # OPA policy for Envoy
├── pyproject.toml          # Python project config
├── server.py               # Unauthenticated MCP server (port 8000)
└── uv.lock

Quick Start

1. Install Dependencies

Install Python dependencies (requires uv):

uv sync

2. Build and Start Services

Build and start all services using Docker Compose:

docker compose up --build -d

3. Test the Clients

Unauthenticated

uv run client.py

Authenticated

Edit client.py to use the authenticated endpoint and provide a valid token.

How It Works

  • server.py: Runs a FastMCP server on port 8000 (no auth).

  • client.py: Example client for both endpoints, supports custom authentication.

  • proxy/: Contains Nginx and Envoy configs for authentication and policy enforcement.

Requirements

  • fastmcp

  • Docker & Docker Compose

  • uv (for Python dependency management)

F
license - not found
-
quality - not tested
D
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    A secure MCP server using FastMCP and Eunomia Authorization, providing granular access control with dynamic JSON policies.
    MIT
  • A
    license
    -
    quality
    B
    maintenance
    Secure MCP protocol proxy with OAuth2 + Dynamic Client Registration (DCR), JWT auth, RBAC, rate limiting, multi-server aggregation, and a monitoring/admin dashboard.
    11
    MIT
  • F
    license
    -
    quality
    D
    maintenance
    FastMCP server with Bearer token authentication mounted on FastAPI, including OAuth 2.1 endpoints for dynamic client registration and metadata discovery.
  • F
    license
    -
    quality
    C
    maintenance
    A proof-of-concept MCP server implementing OAuth 2.1 authorization with CIMD client registration and PKCE, demonstrating protected resource access and step-up authentication.

View all related MCP servers

Related MCP Connectors

  • Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.

  • Multi-tenant FastMCP server for Charles Schwab brokerage data, monetized via DPYC Tollbooth

  • MCP server for verifying EUDI/Talao wallet data via OIDC4VP (pull) for AI agents.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Jason-CKY/mcp-auth'

If you have feedback or need assistance with the MCP directory API, please join our Discord server