Install
$ agentstack add mcp-sigbit-mcp-auth-proxy ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
MCP Auth Proxy
> If you found value here, please consider starring.
Overview
- Drop-in OAuth 2.1/OIDC gateway for MCP servers — put it in front, no code changes.
- Your IdP, your choice: Google, GitHub, or any OIDC provider — e.g. Okta, Auth0, Azure AD, Keycloak — plus optional password.
- Flexible user matching: Support exact matching and glob patterns for user authorization (e.g.,
*@company.com) - Publish local MCP servers safely: Supports all stdio, SSE, and HTTP transports. For stdio, traffic is converted to
/mcp. For SSE/HTTP, it's proxied as-is. Of course, with authentication. - Verified across major MCP clients: Claude, Claude Code, ChatGPT, GitHub Copilot, Cursor, etc. — the proxy smooths client-specific quirks for consistent auth.
📖 For detailed usage, configuration, and examples, see the Documentation
Quickstart
> Domain binding & 80/443 must be accessible from outside.
Download binary from release page.
If you use stdio transport
./mcp-auth-proxy \
--external-url https://{your-domain} \
--tls-accept-tos \
--password changeme \
-- npx -y @modelcontextprotocol/server-filesystem ./
That's it! Your HTTP endpoint is now available at https://{your-domain}/mcp.
- stdio (when a command is specified): MCP endpoint is https://{your-domain}/mcp.
- SSE/HTTP (when a URL is specified): MCP endpoint uses the backend’s original path (no conversion).
> Already have certificates? Pass --tls-cert-file and --tls-key-file instead of --tls-accept-tos.
Why not MCP Gateway?
mcp-auth-proxy: A lightweight proxy that adds authentication to any MCP server (optional stdio→HTTP(S) conversion) MCP Gateway: A hub to orchestrate multiple MCP servers (aggregation, catalog integration)
When to choose mcp-auth-proxy
- You just need to add auth to one or a few MCPs (enforce OAuth/OIDC/password-only)
- Catalog integration and aggregation aren’t needed (e.g., self-hosted or independently managed MCP deployments)
When to choose MCP Gateway
- You need to manage multiple MCPs centrally (aggregation, policies/permissions, auditing, centralized logging)
- You want catalog integration and aggregation
Note: They are not mutually exclusive. You can put mcp-auth-proxy in front of a Gateway's public endpoint to enforce authentication if the Gateway itself doesn't handle it.
TL;DR: Orchestrate many → Gateway / Expose safely & quickly → mcp-auth-proxy
Verified MCP Client
| MCP Client | Status | Notes | | ----------------- | ------ | ------------------------------------------------ | | Claude - Web | ✅ | | | Claude - Desktop | ✅ | | | Claude Code | ✅ | | | ChatGPT - Web | ✅ | Need to implement search and fetch tools.(1) | | ChatGPT - Desktop | ✅ | Need to implement search and fetch tools.(1) | | GitHub Copilot | ✅ | | | Cursor | ✅ | |
- \*1: https://platform.openai.com/docs/mcp
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sigbit
- Source: sigbit/mcp-auth-proxy
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.