docs/integrations/auth0.mdx
import { VersionBadge } from "/snippets/version-badge.mdx"
<VersionBadge version="2.12.4" />FastMCP supports two Auth0 integration paths:
Auth0MCPProvider). Use this for MCP-native clients and Auth0's Auth for MCP setup.Auth0Provider). Use this when you manage an Auth0 application manually and do not need tenant-level DCR.This path uses the Remote OAuth pattern. Auth0 acts as the authorization server; FastMCP is the resource server.
http://127.0.0.1:8000 in development — not localhost)See Auth0's authorization quickstart for tenant setup (API identifier, domain-level connections, CIMD approval).
Create an API (Resource Server) whose identifier is your MCP resource URL, for example http://127.0.0.1:8000/mcp. Use RS256 signing and the rfc9068_profile_authz token dialect if you need permissions claims on tokens.
When the server starts, it logs the exact aud value it validates — your API identifier must match.
from fastmcp import FastMCP
from fastmcp.server.auth.providers.auth0 import Auth0MCPProvider
auth_provider = Auth0MCPProvider(
config_url="https://YOUR_TENANT.auth0.com/.well-known/openid-configuration",
base_url="http://127.0.0.1:8000",
)
mcp = FastMCP(name="Auth0 MCP Server", auth=auth_provider)
No client_id or client_secret is required on the FastMCP side — MCP clients register with Auth0 directly.
See examples/auth/auth0_mcp/ for a runnable server and DCR client. Set AUTH0_CONFIG_URL to your tenant's OIDC discovery URL before starting the server.
This integration uses the OIDC Proxy pattern when you use a fixed Auth0 application instead of tenant-level DCR.
Before you begin, you will need:
http://localhost:8000)Create an Application in your Auth0 settings to get the credentials needed for authentication:
<Steps> <Step title="Navigate to Applications"> Go to **Applications → Applications** in your Auth0 account.Click **"+ Create Application"** to create a new application.
- **Allowed Callback URLs**: Your server URL + `/auth/callback` (e.g., `http://localhost:8000/auth/callback`)
- Click **Save** to save your changes
<Warning>
The callback URL must match exactly. The default path is `/auth/callback`, but you can customize it using the `redirect_path` parameter.
</Warning>
<Tip>
If you want to use a custom callback path (e.g., `/auth/auth0/callback`), make sure to set the same path in both your Auth0 Application settings and the `redirect_path` parameter when configuring the Auth0Provider.
</Tip>
- **Client ID**: A public identifier like `tv2ObNgaZAWWhhycr7Bz1LU2mxlnsmsB`
- **Client Secret**: A private hidden value that should always be stored securely
<Tip>
Store these credentials securely. Never commit them to version control. Use environment variables or a secrets manager in production.
</Tip>
- Find the API that you want to use for your application
- **API Audience**: A URL that uniquely identifies the API
<Tip>
Store this along with of the credentials above. Never commit this to version control. Use environment variables or a secrets manager in production.
</Tip>
Create your FastMCP server using the Auth0Provider.
from fastmcp import FastMCP
from fastmcp.server.auth.providers.auth0 import Auth0Provider
# The Auth0Provider utilizes Auth0 OIDC configuration
auth_provider = Auth0Provider(
config_url="https://.../.well-known/openid-configuration", # Your Auth0 configuration URL
client_id="tv2ObNgaZAWWhhycr7Bz1LU2mxlnsmsB", # Your Auth0 application Client ID
client_secret="vPYqbjemq...", # Your Auth0 application Client Secret
audience="https://...", # Your Auth0 API audience
base_url="http://localhost:8000", # Must match your application configuration
# redirect_path="/auth/callback" # Default value, customize if needed
)
mcp = FastMCP(name="Auth0 Secured App", auth=auth_provider)
# Add a protected tool to test authentication
@mcp.tool
async def get_token_info() -> dict:
"""Returns information about the Auth0 token."""
from fastmcp.server.dependencies import get_access_token
token = get_access_token()
return {
"issuer": token.claims.get("iss"),
"audience": token.claims.get("aud"),
"scope": token.claims.get("scope")
}
Start your FastMCP server with HTTP transport to enable OAuth flows:
fastmcp run server.py --transport http --port 8000
Your server is now running and protected by Auth0 authentication.
Create a test client that authenticates with your Auth0-protected server:
from fastmcp import Client
import asyncio
async def main():
# The client will automatically handle Auth0 OAuth flows
async with Client("http://localhost:8000/mcp", auth="oauth") as client:
# First-time connection will open Auth0 login in your browser
print("✓ Authenticated with Auth0!")
# Test the protected tool
result = await client.call_tool("get_token_info")
token_info = result.data
print(f"Auth0 audience: {token_info['audience']}")
if __name__ == "__main__":
asyncio.run(main())
When you run the client for the first time:
For production deployments with persistent token management across server restarts, configure jwt_signing_key, and client_storage:
import os
from fastmcp import FastMCP
from fastmcp.server.auth.providers.auth0 import Auth0Provider
from key_value.aio.stores.redis import RedisStore
from key_value.aio.wrappers.encryption import FernetEncryptionWrapper
from cryptography.fernet import Fernet
# Production setup with encrypted persistent token storage
auth_provider = Auth0Provider(
config_url="https://.../.well-known/openid-configuration",
client_id="tv2ObNgaZAWWhhycr7Bz1LU2mxlnsmsB",
client_secret="vPYqbjemq...",
audience="https://...",
base_url="https://your-production-domain.com",
# Production token management
jwt_signing_key=os.environ["JWT_SIGNING_KEY"],
client_storage=FernetEncryptionWrapper(
key_value=RedisStore(
host=os.environ["REDIS_HOST"],
port=int(os.environ["REDIS_PORT"])
),
fernet=Fernet(os.environ["STORAGE_ENCRYPTION_KEY"])
)
)
mcp = FastMCP(name="Production Auth0 App", auth=auth_provider)
For complete details on these parameters, see the OAuth Proxy documentation. </Note>
<Info> The client caches tokens locally, so you won't need to re-authenticate for subsequent runs unless the token expires or you explicitly clear the cache. </Info>