# Authentication and authorization

> How a FrontMCP server authenticates MCP clients and decides what each caller may do: auth modes, tokens and sessions, OAuth sign-in, access rules on tools, resources and prompts, and running it in production.

Source: https://frontmcp.dev/reference/auth

This section covers who may connect to a FrontMCP server, and what each caller may do once they're in. The `auth` option of `@FrontMcp` picks one of five modes: `public` (the default) lets everyone in, `static` checks a shared key, `transparent` checks JWTs your identity provider signed, and `local` and `remote` make FrontMCP the OAuth authorization server that MCP clients sign in with. FrontMCP checks the credential on every request to the MCP endpoint, before any tool, resource or prompt runs. Then `authorities` decide, entry by entry, which callers may use each tool, resource, prompt, skill or agent. It's for anyone putting a server where other people's clients can reach it. Start with [Auth modes](https://frontmcp.dev/reference/auth/modes); [Securing a Server](https://frontmcp.dev/learn/securing-a-server) teaches the same ground step by step.

```ts
@FrontMcp({
  info, apps,
  auth: { mode: "public" | "static" | "transparent" | "local" | "remote", ...options }, // who may connect
  authorities: { profiles, ... },                                                       // named access rules
})
@Tool({ ..., authorities: "agent" }) // who may call this tool
```

---

## Who may connect

| Page | Covers |
| --- | --- |
| [Auth modes](https://frontmcp.dev/reference/auth/modes) | The five ways a server decides who may connect, what each one advertises and answers without credentials, who your code sees as the caller, anonymous access, and how to choose |
| [Tokens and sessions](https://frontmcp.dev/reference/auth/tokens) | How the credential on every request is checked (JWTs from your identity provider, tokens FrontMCP issued, static keys), what your code gets from a token, sessions, expiry, and every error a client can get |

## Signing users in

In `local` and `remote` mode, FrontMCP is the OAuth server: clients discover it, the user signs in, and FrontMCP issues the token the client sends from then on.

| Page | Covers |
| --- | --- |
| [Local auth](https://frontmcp.dev/reference/auth/local) | FrontMCP as its own OAuth 2.1 authorization server: every option, the endpoints it serves, the flow a client follows, and what its tokens hold |
| [Remote and proxied auth](https://frontmcp.dev/reference/auth/remote) | Users sign in at your identity provider, and FrontMCP issues the tokens clients send; what tools see, and how it compares with `transparent` |
| [Custom login UI](https://frontmcp.dev/reference/auth/login-ui) | The sign-in, consent and error pages FrontMCP serves in local mode, how to change or replace them, and what protects them |
| [Upstream providers](https://frontmcp.dev/reference/auth/upstream-providers) | Several OAuth providers the user links while signing in to a local-mode server: `auth.providers`, the provider picker, `federatedAuth`, and each provider's token in tools |
| [Progressive auth](https://frontmcp.dev/reference/auth/progressive) | Starting with part of a local-mode server and granting more when a tool needs it: another app, a credential connected mid-session, or tool consent |
| [Client ID metadata (CIMD)](https://frontmcp.dev/reference/auth/cimd) | Clients whose `client_id` is the URL of a metadata document instead of a registration: what FrontMCP fetches and checks, caching, and SSRF protection |

## What each caller may do

| Page | Covers |
| --- | --- |
| [Authorities](https://frontmcp.dev/reference/auth/authorities) | Rules on tools, resources, prompts, skills and agents that decide who may call them, from roles, permissions, token claims, the call's arguments or your own code, and what a refused caller gets |
| [`this.auth`](https://frontmcp.dev/reference/sdk/auth) | Who is calling, inside your code: their scopes, roles and claims, and what each auth mode and entry point fills in |

## Running it in production

| Page | Covers |
| --- | --- |
| [Auth in production](https://frontmcp.dev/reference/auth/production) | The checklist before a server authenticates real users: secrets, HTTPS and allowed hosts, token checks, what production hides, rate limits and several instances |

## Which page for which task

| You want to | Read |
| --- | --- |
| Choose an auth mode | [Choosing a mode](https://frontmcp.dev/reference/auth/modes#choosing-a-mode) |
| Let in only clients that send a key you gave them | [Static keys](https://frontmcp.dev/reference/auth/tokens#static-keys) |
| Accept tokens from Auth0, Okta, Keycloak or Entra ID | [Accepting tokens from your identity provider](https://frontmcp.dev/reference/auth/tokens#accepting-tokens-from-your-identity-provider) |
| Find out why a client's token gets `401` | [Seeing why a token is refused](https://frontmcp.dev/reference/auth/tokens#seeing-why-a-token-is-refused) |
| Sign users in with no identity provider behind the server | [Local auth](https://frontmcp.dev/reference/auth/local) |
| Sign users in at your identity provider, through FrontMCP | [Remote and proxied auth](https://frontmcp.dev/reference/auth/remote), and [choosing between `transparent` and `remote`](https://frontmcp.dev/reference/auth/remote#choosing-between-transparent-and-remote) |
| Let tools call several services, like a chat and a CRM, as the user | [Upstream providers](https://frontmcp.dev/reference/auth/upstream-providers) |
| Change the sign-in or consent page | [Custom login UI](https://frontmcp.dev/reference/auth/login-ui) |
| Let anonymous callers use some tools and not others | [Limiting what anonymous callers can use](https://frontmcp.dev/reference/auth/modes#limiting-what-anonymous-callers-can-use) |
| Let only some roles call a tool | [Naming rules as profiles](https://frontmcp.dev/reference/auth/authorities#naming-rules-as-profiles) |
| Give one app its own auth | [Auth for one app](https://frontmcp.dev/reference/auth/modes#auth-for-one-app) |
| Ask for an API key only when a tool needs it | [Asking for a credential when a tool needs it](https://frontmcp.dev/reference/auth/progressive#asking-for-a-credential-when-a-tool-needs-it) |
| Accept clients that never registered with your server | [Client ID metadata (CIMD)](https://frontmcp.dev/reference/auth/cimd) |
| Run behind a proxy that terminates TLS | [The server's public address](https://frontmcp.dev/reference/auth/modes#the-servers-public-address) |
| Check a server before real users sign in | [Auth in production](https://frontmcp.dev/reference/auth/production#the-checklist) |
| Test a server that needs a token | [Testing authentication](https://frontmcp.dev/reference/testing/auth) |

## Related pages

- [Guard options](https://frontmcp.dev/reference/sdk/guard): rate limits, concurrency caps, timeouts and IP filters, per tool and per server.
- [Apps, discovery and splitting](https://frontmcp.dev/reference/server/apps#endpoints-standalone-and-splitbyapp): the endpoints where an app's own `auth` applies.
- [Remote servers](https://frontmcp.dev/reference/server/remote#authenticating-to-the-remote-server): authenticating your server to another MCP server it mounts.
- [Security headers and transport](https://frontmcp.dev/reference/deployment/security): host checks, CORS, body limits and the headers FrontMCP sends.
- Learn: [Authenticating Clients](https://frontmcp.dev/learn/authenticating-clients) and [Deciding Who Can Call What](https://frontmcp.dev/learn/authorizing-calls).
