Skip to content

Securing MCP with OAuth 2.0

Albert Skibinski •
You get a key and you get a key and you get a key

In a previous post, I managed to get MCP working to manage content on Jafix. This was pretty cool, but it had issues:

  • It wasn't very secure
  • It was pretty hard to set up

Over the past week I’ve worked on adding OAuth 2.0 support to the Jafix MCP server. Now, anybody with an account on Jafix (free) can add it as a MCP server and use it for the same thing you can do on the platform (as basic user): create, update and manage your own tutorials. 

Demo of using the Jafix MCP with Claude.ai

Note: currently you will need a paid account for Claude to be able to add custom connectors.

Instead of relying on API keys or custom tokens, clients can now use the familiar OAuth flow to request access, with proper consent screens and fine-grained scopes. In practice this means:

  • Standard OAuth flows with PKCE for secure, password-less client apps
  • Dynamic Client Registration (DCR), so new tools can set themselves up automatically
  • Scopes mapped to Drupal permissions, keeping authorization aligned with your existing permissions
  • Public clients without secrets, a safer way to connect apps like MCP Inspector

Why it matters

For developers this removes a lot of friction. Instead of hand-configuring clients and tokens, MCP servers can advertise their capabilities via standard metadata endpoints (/.well-known/oauth-authorization-server), and clients can register themselves on the fly. From there, the PKCE flow ensures secure token exchange even for public clients like browser-based tools.

For administrators it also means better control. Scopes can be mapped directly to Drupal permissions, so you don’t end up with a parallel universe of access rules. Users still have to approve access on a consent screen, and tokens can be revoked or rotated as needed.

For end-users this means they can easily connect to a server from a client, without the hassle of api keys. The only thing you need is the url of the MCP server.

Looking ahead

OAuth integration makes MCP a lot more production-ready. It opens the door for wider adoption, since security and authorization are no longer “custom” but handled through standards everyone already knows. 

It also makes it easier to implement your server as part in orchestration tools. But most imporantly I expect that all Ai clients will provide a way to connect to MCP servers. Currently you often need a paid subscription and adding it is still only for advanced users but this will probably become easier in the future. Claude already has a list of approved connectors which you could see in above video.

Developers

Oauth Dynamic Client Registration (DCR) was new for me. The php league oauth2 library does not support DRC, so that was something which needed manual implementation.

If you’re experimenting with MCP and Oauth, I strongly recommend trying out the OAuth flow with MCP Inspector which has a very nice Oauth debug guide tool:
 

Demo of MCP inspector with Oauth


 

Albert Skibinski

About the author

  • Albert Skibinski is a freelance full-stack developer en co-founder at Jafix.
  • I write about web development, long bike rides and food!