adding-mcp-oauth
Installation
SKILL.md
Adding OAuth 2.1 Authorization to MCP Servers
Guardrails
- MUST use Streamable HTTP transport — stdio does not support OAuth.
- MUST validate the bearer token's audience (and required scopes, if enforcing scope-based authorization) before executing any tool logic.
- MUST NOT protect the
/.well-known/oauth-protected-resourcediscovery endpoint with auth middleware — it must remain publicly accessible. - MUST return 401 with a
WWW-Authenticateheader on missing or invalid tokens; a bare 401 causes AI hosts to fail silently.
Prerequisite: HTTP transport
MCP OAuth requires Streamable HTTP transport. Stdio does not support OAuth.
Node.js: Use StreamableHTTPServerTransport from @modelcontextprotocol/sdk/server/streamableHttp.js
Python: Use mcp.streamable_http_app(path="/mcp") and run with uvicorn module:app
If currently using stdio, migrate to HTTP first. See MCP Transport Docs.