ping-iga-mcp-server
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ping-iga-mcp-serverlist my pending approvals"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ping-iga-mcp-server
MCP server exposing Ping IGA self-service governance operations — access requests, approvals, certifications, and manual tasks — to MCP clients, acting on behalf of the authenticated user.
Stack: JavaScript (ES modules) on Node 20 + Express. No TypeScript, no build step. Zod for runtime validation. MCP 2026-07-28 stateless transport.
Status: Phase 1 complete. Auth (introspection, throttle, rate-limit, RFC 9728 metadata) is wired. The
/mcpendpoint and governance tools are built out phase by phase per the implementation plan.
Requirements
Node 20 LTS (
.nvmrcpins20)
Related MCP server: governance-mcp-server
Getting started
nvm use # Node 20
npm install
cp .env.example .env # adjust as needed
npm run dev # starts with --watch on http://localhost:3000
curl http://localhost:3000/healthz # -> {"status":"ok"}Scripts
Script | Purpose |
| Start with |
| Start once |
| Run vitest |
| ESLint |
| Prettier write |
| Launch MCP Inspector against the server |
401 → metadata → token walkthrough
With the server running (npm run dev) and .env populated, the full bootstrap flow can be traced manually:
Step 1 — hit a protected route without a token; receive a metadata pointer
curl -si http://localhost:3000/_authcheck
# HTTP/1.1 401
# WWW-Authenticate: Bearer resource_metadata="https://<PUBLIC_URL>/.well-known/oauth-protected-resource"Step 2 — fetch the resource-server metadata document (no token needed)
curl -s http://localhost:3000/.well-known/oauth-protected-resource | jq .
# {
# "resource": "https://<PUBLIC_URL>",
# "authorization_servers": ["https://<AIC_BASE_URL>/am/oauth2"],
# "scopes_supported": ["iga:read", "iga:write", "iga:mutate"],
# "bearer_methods_supported": ["header"]
# }Step 3 — obtain a token from the authorization server listed above
Use the authorization_servers[0] URL with your preferred OAuth 2.0 flow
(client credentials, authorization code, device flow — whichever your AIC
tenant and client registration support). The resulting access token must have
at least the iga:read scope.
Step 4 — call the probe route with the token
TOKEN=<access token from step 3>
curl -si http://localhost:3000/_authcheck \
-H "Authorization: Bearer $TOKEN"
# HTTP/1.1 200
# {"sub":"<user>","scopes":["iga:read",...]}/_authcheck is a throwaway probe route (D1=a) that will be removed when
/mcp lands in Phase 2.
Deployment prerequisites
Beyond the skeleton, running the server against a tenant requires AIC configuration (a confidential client for token introspection, MCP tool-gating scopes, client registration, and verification of the tenant's token model). These are enumerated in the implementation plan and expanded in this README as each phase lands.
WebStorm
Shared run configurations for dev, test, and inspector are committed under
.run/. Open the project folder in WebStorm; set the project Node interpreter to
your Node 20 install. The .idea/ folder is intentionally not committed — WebStorm
generates it on first open.
This server cannot be installed
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseBquality-maintenanceAn MCP server that enables interaction with SailPoint IdentityNow and Identity Security Cloud for identity governance and access management. It provides comprehensive tools to manage identities, accounts, roles, workflows, and certifications through API integration.Last updated36
- Alicense-qualityDmaintenanceMCP server for querying the DodaOne governance framework, enabling users to retrieve governance information and evaluate proposed actions.Last updated2MIT
- Flicense-qualityCmaintenanceAn MCP server that implements a multi-stage employee access request and approval workflow, enabling employees to request system access and managers/IT admins to approve or reject requests through an interactive UI.Last updated
- AlicenseAqualityBmaintenanceMCP server that lets an AI assistant perform scoped Okta identity operations with an out-of-band human-approval gate on destructive actions.Last updated5MIT
Related MCP Connectors
Remote MCP for A2A caller identity, scope policy, verdict receipts, and audit history.
MCP Server for agents to onboard, pay, and provision services autonomously with InFlow
Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/srallapally/iga-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server