Remote MCP servers expose data and actions over the network, so they need proper authorisation.
OAuth-Based Flow
The MCP specification builds authorisation for HTTP transports on OAuth 2.1 conventions. In outline:
- The client connects and the server indicates that authorisation is required.
- The client discovers the authorisation server from published metadata.
- The user signs in and consents in a browser.
- The client receives an access token and sends it with each request.
The exact discovery and registration mechanisms have evolved between protocol versions; follow the version your SDK implements.
Good Practice
- Least privilege: request narrow scopes that match the tools offered.
- Short-lived tokens with refresh, stored securely by the client.
- Validate tokens on every request, including the intended audience, so tokens issued for another service aren't accepted.
- Don't pass tokens through: a server calling other APIs should obtain its own credentials rather than forwarding the client's token.
- Per-user authorisation: apply the signed-in user's permissions to every tool call.
Local Servers
stdio servers usually rely on local credentials such as environment variables or config files. Keep these out of source control and give them minimal permissions.
Audit
Log who called which tool with what outcome.