Skip to main content
Glama
autodesk-platform-services

APS MCP Auth Examples

Official

APS MCP Auth Examples

Reference implementations of MCP servers that integrate with Autodesk Platform Services, covering every combination of:

  • How the server authenticates to APS

    • 2LO - 2-legged OAuth, app-wide

    • 3LO - 3-legged OAuth, per-user

    • PKCE - 3-legged OAuth for public clients, per-user

    • SSA - Secure Service Account, non-human identity

  • How MCP clients authenticate to the server

    • not at all (STDIO)

    • via an external identity provider

    • via an OAuth proxy service

All HTTP-based examples target the 2026-07-28 MCP specification revision via the split MCP TypeScript SDK v2 (@modelcontextprotocol/{server,express,node}), which requires MCP servers to act as OAuth 2.1 resource servers backed by a dedicated authorization server, and prefers Client ID Metadata Documents (CIMD) over Dynamic Client Registration for identifying MCP clients.

Every example exposes the same MCP tools, implemented once in shared/ and reused everywhere: list-projects (hubs + projects, via the Data Management API) and list-contents (a project's top-level folders, or a specific folder's contents).

The examples

Folder

MCP-client auth

What it demonstrates

aps-mcp-server-local

none (STDIO)

The simplest possible setup — a locally spawned process, no MCP-layer auth at all.

aps-mcp-server-remote-auth0

External IdP (Auth0)

This server only verifies tokens; Auth0 (or any OIDC/JWKS provider) remains the authorization server. Per-IdP-user APS providers cached in memory.

aps-mcp-server-remote-proxy

Separate OAuth proxy service

Relies on an OAuth proxy in front of APS authentication (simple-oauth-proxy) to generate "MCP tokens", and uses /internal/exchange endpoint to exchange these for "APS tokens".

simple-oauth-proxy

(is the proxy)

The standalone, provider-agnostic OAuth proxy service consumed by aps-mcp-server-remote-proxy, built with Python + FastMCP.

shared

(library)

The five APS auth provider classes, the two MCP tools, and small helpers reused by every example above.

Related MCP server: Devcon MCP Workshop 2026

Setup common to every example

  1. Register an APS application at https://aps.autodesk.com/myapps (a Traditional Web App if you'll use any 3LO example; a Server-to-Server / API-key style app is enough for 2LO-only use). For SSA, additionally create a Secure Service Account and register its public key — see the SSA guide.

  2. npm install at the repo root — this is an npm workspaces project, so one install resolves shared and all four TypeScript servers.

  3. Run any TypeScript example with npm start from inside its folder (or npm run start -w <package-name> from the root), after copying its .env.example to .env and filling in the values for your chosen APS_AUTH_MODE.

  4. simple-oauth-proxy is a separate Python/FastMCP service — see its own README for setup; it's only needed if you're trying aps-mcp-server-remote-proxy.

A note on scope

These are teaching examples, optimized to be read end-to-end in one sitting. Several corners intentionally cut for brevity are called out in the relevant README (in-memory-only state with no horizontal-scaling story, a simplified CIMD fetch without full SSRF hardening in the OAuth proxy example, etc.). Don't copy the security-relevant bits verbatim into production without reading those notes.

A
license - permissive license
Not graded
quality - not tested
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    A
    quality
    C
    maintenance
    An MCP server that exposes Autodesk Platform Services (APS) as tools for AI assistants to interact with the APS Data Management API. It enables users to authenticate and manage hubs, projects, and folders through a standardized interface.
    27
    2
  • F
    license
    Not graded
    quality
    C
    maintenance
    Example MCP server for Autodesk Platform Services that demonstrates proper OAuth authorization with Auth0 as the first layer and APS 3-legged OAuth as the second layer. Enables querying APS projects and issues through natural language after authenticating via Auth0 and APS.
  • A
    license
    Not graded
    quality
    C
    maintenance
    A complete MCP server implementation demonstrating all protocol features (tools, resources, prompts, sampling, and elicitation) with OAuth authentication, serving as a learning resource and starting template for building MCP servers.
    MIT

View all related MCP servers

Related MCP Connectors

  • A MCP server built for developers enabling Git based project management with project and personal…

  • The official MCP Server from Mia-Platform to interact with Mia-Platform Console

  • Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/autodesk-platform-services/aps-mcp-auth-examples'

If you have feedback or need assistance with the MCP directory API, please join our Discord server