-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path10-auth-server.yaml
More file actions
43 lines (38 loc) · 1.65 KB
/
Copy path10-auth-server.yaml
File metadata and controls
43 lines (38 loc) · 1.65 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# Embedded OAuth authorization server: MCP clients OAuth against the
# GATEWAY itself, with no pre-shared tokens.
#
# The gateway serves RFC 8414 metadata, JWKS, RFC 7591 dynamic client
# registration, /authorize (PKCE required), and /token. A client like
# Claude Code discovers all of it from the 401 challenge and runs the
# browser flow.
#
# With `upstream` set, login federates to your company IdP: the user
# authenticates there, the gateway issues its own (ES256) access token for
# the MCP session, and KEEPS the upstream tokens. Backends with
# `auth: upstream_swap`-style needs can reuse them (see swap note below).
#
# Without `upstream`, /authorize auto-approves a local dev identity and
# logs a warning. Dev only.
listen: 127.0.0.1:8000
# inbound.mode has no effect when auth_server is set: the gateway
# validates its own issued tokens.
inbound:
mode: anonymous
auth_server:
issuer: http://127.0.0.1:8000 # external URL of this gateway
signing_key_file: ${HOME}/.mcpproxy/authserver.pem # generated if absent
access_token_ttl: 1h
upstream: # federate login to a company IdP
issuer: https://accounts.google.com
client_id: ${IDP_CLIENT_ID}
client_secret: ${IDP_CLIENT_SECRET}
scopes: ["openid", "email", "profile"]
backends:
everything:
transport: stdio
command: ["npx", "-y", "@modelcontextprotocol/server-everything"]
# Upstream-swap: a backend can reuse the caller's stored upstream IdP token
# as its outbound credential, so the user's own identity reaches the MCP
# server. You wire it in code when embedding
# (authserver.NewUpstreamSwapSource); daemon-level YAML wiring is on the
# roadmap.