Set up Casdoor for your MCP server
This guide explains how to make Casdoor the authorization server of your own MCP server: first the configuration in Casdoor, then the changes to your MCP server.
Learning outcomes
- Create an application with custom scopes for your MCP server.
- Let MCP clients register themselves.
- Publish Protected Resource Metadata and challenge unauthenticated requests.
- Validate tokens and enforce scopes in your tools.
What you need
- A running Casdoor instance and administrator access to it. See Install the Casdoor server.
- The public URL of your MCP server, for example
https://your-mcp-server.com