Authentication and authorization

This section covers who may connect to a FrontMCP server, and what each caller may do once they're in. The auth option of @FrontMcp picks one of five modes: public (the default) lets everyone in, static checks a shared key, transparent checks JWTs your identity provider signed, and local and remote make FrontMCP the OAuth authorization server that MCP clients sign in with. FrontMCP checks the credential on every request to the MCP endpoint, before any tool, resource or prompt runs. Then authorities decide, entry by entry, which callers may use each tool, resource, prompt, skill or agent. It's for anyone putting a server where other people's clients can reach it. Start with Auth modes; Securing a Server teaches the same ground step by step.

@FrontMcp({
  info, apps,
  auth: { mode: "public" | "static" | "transparent" | "local" | "remote", ...options }, // who may connect
  authorities: { profiles, ... },                                                       // named access rules
})
@Tool({ ..., authorities: "agent" }) // who may call this tool

Who may connect

PageCovers
Auth modesThe five ways a server decides who may connect, what each one advertises and answers without credentials, who your code sees as the caller, anonymous access, and how to choose
Tokens and sessionsHow the credential on every request is checked (JWTs from your identity provider, tokens FrontMCP issued, static keys), what your code gets from a token, sessions, expiry, and every error a client can get

Signing users in

In local and remote mode, FrontMCP is the OAuth server: clients discover it, the user signs in, and FrontMCP issues the token the client sends from then on.

PageCovers
Local authFrontMCP as its own OAuth 2.1 authorization server: every option, the endpoints it serves, the flow a client follows, and what its tokens hold
Remote and proxied authUsers sign in at your identity provider, and FrontMCP issues the tokens clients send; what tools see, and how it compares with transparent
Custom login UIThe sign-in, consent and error pages FrontMCP serves in local mode, how to change or replace them, and what protects them
Upstream providersSeveral OAuth providers the user links while signing in to a local-mode server: auth.providers, the provider picker, federatedAuth, and each provider's token in tools
Progressive authStarting with part of a local-mode server and granting more when a tool needs it: another app, a credential connected mid-session, or tool consent
Client ID metadata (CIMD)Clients whose client_id is the URL of a metadata document instead of a registration: what FrontMCP fetches and checks, caching, and SSRF protection

What each caller may do

PageCovers
AuthoritiesRules on tools, resources, prompts, skills and agents that decide who may call them, from roles, permissions, token claims, the call's arguments or your own code, and what a refused caller gets
this.authWho is calling, inside your code: their scopes, roles and claims, and what each auth mode and entry point fills in

Running it in production

PageCovers
Auth in productionThe checklist before a server authenticates real users: secrets, HTTPS and allowed hosts, token checks, what production hides, rate limits and several instances

Which page for which task

You want toRead
Choose an auth modeChoosing a mode
Let in only clients that send a key you gave themStatic keys
Accept tokens from Auth0, Okta, Keycloak or Entra IDAccepting tokens from your identity provider
Find out why a client's token gets 401Seeing why a token is refused
Sign users in with no identity provider behind the serverLocal auth
Sign users in at your identity provider, through FrontMCPRemote and proxied auth, and choosing between transparent and remote
Let tools call several services, like a chat and a CRM, as the userUpstream providers
Change the sign-in or consent pageCustom login UI
Let anonymous callers use some tools and not othersLimiting what anonymous callers can use
Let only some roles call a toolNaming rules as profiles
Give one app its own authAuth for one app
Ask for an API key only when a tool needs itAsking for a credential when a tool needs it
Accept clients that never registered with your serverClient ID metadata (CIMD)
Run behind a proxy that terminates TLSThe server's public address
Check a server before real users sign inAuth in production
Test a server that needs a tokenTesting authentication