MCP Front
About
An OAuth 2.1 proxy for MCP servers that enables single sign-on with Google, domain validation, and per-user tokens.
Details
- Author
- dgellow
- Categories
- Developer Tools, Security, API
Jump to
Setup
Install MCP Front in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/dgellow/mcp-front
Follow the installation instructions in the repository README, then restart your MCP client.
[!WARNING]This project is a work in progress and should not be considered production ready.
Though I'm fairly confident the overall architecture is sound, and I myself rely on the implementation — so itshould work :tm:. But definitely alpha software.
Also, don't rely too much on the docs, they drift fairly quickly, I do not always keep them updated when doing changes or adding/removing features. They are mostly here to anchor me and help me stay focus on my initial vision.
[!TIP] Looking for the easiest way to get an MCP server for your API? Check outStainless✨. We offer best-in-class SDK and MCP generation. Build a complete MCP server andpublish it to Cloudflare and Docker Hubin a few minutes!
Disclaimer: the author of mcp-front is an early Stainless employee
An authentication gateway forMCP (Model Context Protocol)servers. Let your team use Claude with internal databases, APIs, and tools without exposing them to the internet.
You want your team to use Claude with internal MCP servers (databases, Linear, Notion, internal APIs). But MCP servers don't have built-in multi-user authentication. You either expose them to the public internet, build authentication yourself, or run separate instances per user. None of these are great.
mcp-front sits between Claude and your MCP servers as an authentication gateway. Your team authenticates via OAuth once (Google, Azure AD, GitHub, or any OIDC provider). When Claude connects, mcp-front validates the token, checks the user belongs to your organization, and proxies to the actual MCP server in your secure environment.
For stdio servers, each user gets an isolated subprocess. For services that need individual API keys (Notion, Linear), users connect them once through a web UI and mcp-front injects tokens automatically. Tokens are scoped to specific services (RFC 8707) — a token for your Postgres server won't work for Linear.
Organization-wide access control with per-user isolation. No modifications to your MCP servers. Nothing exposed to the internet.
- User addshttps://your-domain.com/<service>/sseto Claude
- Claude redirects to the identity provider for login (first time only)
- mcp-front validates the user belongs to your organization
- If the service needs a user API key (Notion, Linear), user connects it through a web page
- mcp-front proxies all MCP requests to the backend server
{ "version": "v0.0.1-DEV_EDITION_EXPECT_CHANGES", "proxy": { "baseURL": "http://localhost:8080", "addr": ":8080" }, "mcpServers": { "filesystem": { "transportType": "stdio", "command": "npx", "args": ["-y", "@modelcontextprotocol/server-filesystem", "/tmp"], "serviceAuths": [ { "type": "bearer", "tokens": ["dev-token-123"] } ] } } }
# With Go go install github.com/stainless-api/mcp-front/cmd/mcp-front@main mcp-front -config config.json # Or with Docker docker run -p 8080:8080 -v $(pwd)/config.json:/app/config.json dgellow/mcp-front:latest
In Claude.ai, add an MCP server with URLhttp://localhost:8080/filesystem/sse, auth type Bearer Token, tokendev-token-123.
See theQuickstartfor a full walkthrough.
Identity Providers— Set up Google, Azure AD, GitHub, or any OIDC provider for production OAuth.
Configuration— All config options including Firestore persistence, HTTPS, and per-user service authentication.
Server Types— Stdio, SSE, streamable HTTP, inline tools, and aggregate endpoints.
Service Authentication— Per-user tokens for services like Notion, Linear, and other OAuth or API key services.
Architecture— Per-service audience validation, token flow, and MCP spec compliance.
API Reference— HTTP endpoints, OAuth discovery, and client registration.
mcp-front uses OAuth 2.0 with PKCE for public clients, domain and organization-based access control, per-user session isolation for stdio servers, per-service audience claims (RFC 8707) to prevent token reuse across services, and AES-256-GCM encryption for sensitive data at rest.
Security boundary: mcp-front handles authentication. MCP servers handle authorization and input validation. Only use MCP servers you trust with your data.
Copyright 2025 Samuel "dgellow" El-Borai (sam@elborai.me)
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
Enterprise-grade authentication with secure credential management, multi-protocol support, and real-time threat detection.
Hosted OAuth 2.1 + Dynamic Client Registration (RFC 7591) for MCP servers
An MCP server for Keycloak administration, offering over 30 tools to manage users, realms, clients, roles, and more from AI assistants.
A sample MCP server that uses Asgardeo for client authentication and connection.
ZeroID Agent Identity is a paid hosted remote MCP for ZeroID. It exposes Streamable HTTP tool calls, bearer-token access, public server-card metadata, usage logs, and receipt-oriented JSON f
A read-only MCP server that allows LLMs to query live PingOne data. Requires a separate CData JDBC Driver for PingOne.
Interact with Descope's Management APIs to search and retrieve project information.
Administer Keycloak users and realms using a Model Context Protocol server.
A RESTful API to programmatically interact with the Opal Security platform.
Salesforce integration using OAuth2. Write operations disabled by default per integration. 700+ tools covering SOQL, SOSL, REST, and CRUD, individually selectable. Requires a DataGrout account.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





