MCP Auth Example
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Auth Examplelist tools using bearer token auth"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
MCP Auth Example
This project demonstrates a FastMCP server with both authenticated and unauthenticated endpoints. Bearer token authentication is enforced at the Nginx proxy layer. Envoy acts as a reverse proxy, forwarding requests to the MCP server and integrating with Open Policy Agent (OPA) for fine-grained authorization decisions. The repository includes example clients and a Docker setup for running all components together.
Features
FastMCP server with and without authentication
Example Python clients for both endpoints
Docker Compose setup with Nginx, Envoy, and OPA integration
Related MCP server: AuthMCP Gateway
Project Structure
.
├── Dockerfile # Dockerfile for MCP server
├── README.md
├── client.py # Example client for both endpoints
├── docker-compose.yml # Docker Compose setup (Nginx, Envoy, OPA, MCP)
├── proxy
│ ├── envoy # Envoy config
│ │ ├── Dockerfile
│ │ ├── entrypoint.sh
│ │ └── envoy.yaml
│ ├── nginx.conf # Nginx config for Bearer auth
│ └── policy.rego # OPA policy for Envoy
├── pyproject.toml # Python project config
├── server.py # Unauthenticated MCP server (port 8000)
└── uv.lockQuick Start
1. Install Dependencies
Install Python dependencies (requires uv):
uv sync2. Build and Start Services
Build and start all services using Docker Compose:
docker compose up --build -dMCP server (unauthenticated): http://localhost:8000/mcp/
MCP server (authenticated, via Nginx): http://localhost/mcp/
3. Test the Clients
Unauthenticated
uv run client.pyAuthenticated
Edit client.py to use the authenticated endpoint and provide a valid token.
How It Works
server.py: Runs a FastMCP server on port 8000 (no auth).client.py: Example client for both endpoints, supports custom authentication.proxy/: Contains Nginx and Envoy configs for authentication and policy enforcement.
Requirements
This server cannot be deployed
Maintenance
Related MCP Connectors
Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
MCP server for mandates, delegation, policy-gated execution, credential grants, and audit.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Authenticated MCP server for ClearPolicy policy and compliance workflows.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceA secure MCP server using FastMCP and Eunomia Authorization, providing granular access control with dynamic JSON policies.MIT
- AlicenseNot gradedqualityBmaintenanceSecure MCP protocol proxy with OAuth2 + Dynamic Client Registration (DCR), JWT auth, RBAC, rate limiting, multi-server aggregation, and a monitoring/admin dashboard.12MIT
- FlicenseNot gradedqualityDmaintenanceFastMCP server with Bearer token authentication mounted on FastAPI, including OAuth 2.1 endpoints for dynamic client registration and metadata discovery.-
- FlicenseNot gradedqualityDmaintenanceA proof-of-concept MCP server implementing OAuth 2.1 authorization with CIMD client registration and PKCE, demonstrating protected resource access and step-up authentication.-