Skip to main content
Glama
jlavoieca

Access Self-Hosted MCP Server

by jlavoieca

MCP Server + Access Self-Hosted App

A Model Context Protocol (MCP) server protected by Cloudflare Access as a self-hosted application. Unlike the Access for SaaS demo, this approach requires no OAuth implementation — Cloudflare Access handles authentication automatically.

The MCP server demonstrates:

  • Validating the Access JWT signature against your team's public keys using jose

  • Verifying the JWT issuer and audience claims

  • Reading user identity from the validated JWT

  • Conditionally exposing tools based on user identity

Getting Started

Clone the repo and install dependencies:

npm install

Create a self-hosted Access application

  1. In Cloudflare One, go to Access controls > Applications > Add an application > Self-hosted.

  2. Set the Application domain to your Worker URL (e.g., mcp-access-self-hosted.<your-subdomain>.workers.dev).

  3. Add an Access policy to control who can connect (e.g., allow emails ending in @yourcompany.com).

Configure environment variables

Update wrangler.jsonc with your Access application details:

  • TEAM_DOMAIN: Your Cloudflare One team domain (e.g., https://<your-team-name>.cloudflareaccess.com)

  • POLICY_AUD: Your application's AUD tag (found under Access controls > Applications > your app > Basic information)

Deploy

wrangler deploy

Test

Test the remote server using Inspector:

npx @modelcontextprotocol/inspector@latest

Enter https://mcp-access-self-hosted.<your-subdomain>.workers.dev/mcp and connect. You will be prompted to log in through your Access identity provider.

Connect from Claude Desktop

Open Claude Desktop, go to Settings > Developer > Edit Config, and add:

{
	"mcpServers": {
		"access-self-hosted": {
			"type": "http",
			"url": "https://mcp-access-self-hosted.<your-subdomain>.workers.dev/mcp"
		}
	}
}

Local Development

wrangler dev

Note: In local development, Cf-Access-Jwt-Assertion is not set by Access. You can test by manually setting the header or by using cloudflared access to tunnel through Access.

A
license - permissive license
-
quality - not tested
C
maintenance

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    C
    maintenance
    A Cloudflare Workers-based MCP server that enables secure remote connections using built-in OAuth authentication via Cloudflare Access. It provides identity-based access control for MCP tools and supports persistent state management through Durable Objects and SSE.
    Last updated
  • F
    license
    -
    quality
    C
    maintenance
    An MCP server protected by Cloudflare Access as a self-hosted application, validating Access JWT and conditionally exposing tools based on user identity.
    Last updated
  • F
    license
    -
    quality
    C
    maintenance
    Remote MCP server with built-in OAuth authentication via Cloudflare Access, enabling secure tool usage like math and image generation with user-based access control.
    Last updated

View all related MCP servers

Related MCP Connectors

  • Cloudflare Workers MCP server: email-validator

  • MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.

  • An MCP server for Arcjet - the runtime security platform that ships with your AI code.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/jlavoieca/mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server