Ana içeriğe geç

MCP authentication

Requests to the Casdoor MCP server at /api/mcp are authenticated in the same ways as requests to the Casdoor API. This page describes how a client discovers what the server requires, and how each authentication method affects the tools that the client can call.

OAuth discovery​

Casdoor publishes OAuth 2.0 Protected Resource Metadata (RFC 9728), so that an MCP client can find out which authorization server protects the MCP endpoint:

curl https://your-casdoor.com/.well-known/oauth-protected-resource

The response names the authorization server:

{
"resource": "https://your-casdoor.com",
"authorization_servers": ["https://your-casdoor.com"],
"bearer_methods_supported": ["header"],
"scopes_supported": ["openid", "profile", "email"]
}

To get the metadata of a single application, put the application name in the path:

curl https://your-casdoor.com/.well-known/my-app/oauth-protected-resource

Use the application-specific endpoint when applications have different authorization requirements.

Authentication methods​

MethodTools that the client can callUse it for
Access tokenThe tools that the scopes of the token allow. See MCP authorization and scopesAutomation and MCP clients. This is the recommended method
Client ID and client secretThe tools that the application may useService accounts
Session cookieAll tools, without scope checksInteractive use in the browser

With an access token:

curl -X POST https://your-casdoor.com/api/mcp \
-H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

With the client ID and client secret of an application:

curl -X POST https://your-casdoor.com/api/mcp \
-u "CLIENT_ID:CLIENT_SECRET" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Unauthenticated requests​

Casdoor answers a request without credentials with a JSON-RPC error:

{
"jsonrpc": "2.0",
"id": 1,
"error": {
"code": -32001,
"message": "Unauthorized",
"data": "Unauthorized operation"
}
}

The response also carries the header WWW-Authenticate: Bearer realm="/.well-known/oauth-protected-resource". An MCP client that follows the OAuth 2.0 specification reads the metadata from that location and starts the authorization flow on its own.

See also​