documentation /api provider

MCP OAuth

API provider

OAuth 2.1 connection to an MCP server that needs nothing registered in advance: the app discovers the server’s authorization server (RFC 9728, RFC 8414), registers itself there as a client (RFC 7591) with its own redirect URI, and then runs the ordinary authorization-code flow with PKCE and an RFC 8707 resource indicator. The only setting is the MCP server’s endpoint URL. Use MCP Broker instead when the authorization server does not offer open dynamic registration and Nectry’s broker holds a client registered with it in advance (HubSpot’s MCP Auth Apps, say), or the OAuth2 provider when a client was registered by hand for this app alone.

  • API category: Generic
  • Needs login: Yes, three-legged: each end-user must complete an OAuth-style login flow

Configuration parameters

Required

  • title : string; required
    Human-readable label for this connection, shown to end-users on the login button and sent to the authorization server as the registered client’s name.
  • serverUrl : string; required
    The MCP server’s endpoint URL, e.g. https://example.com/mcp. Both the resource this connection’s tokens are for and the starting point of discovery: the app asks this URL which authorization server protects it. $ENV_VAR at the start of the value is resolved from the app’s environment at request time.

What components can use this API

Concepts:

Ingredients: