Authentication
Most MCP Servers expose capabilities that interact with sensitive systems and data.
Examples include:
- Source code repositories
- Internal APIs
- Databases
- Ticketing systems
- Business applications
As a result, authentication is a critical part of any MCP integration.
Karyam provides secure mechanisms for authenticating with MCP Servers while ensuring credentials remain protected.
Supported Authentication Methods
Section titled “Supported Authentication Methods”Karyam currently supports the following authentication methods:
- No Authentication
- OAuth 2.0
- Custom Request Headers
No Authentication
Section titled “No Authentication”Some MCP Servers operate in trusted environments and do not require authentication.
Examples include:
- Local development servers
- Internal test environments
- Air-gapped deployments
Configuration:
Authentication Type:NoneOAuth 2.0
Section titled “OAuth 2.0”OAuth 2.0 is the recommended authentication mechanism for production environments.
It provides:
- Secure token exchange
- Delegated authorization
- Credential isolation
- Revocable access
Karyam supports two OAuth modes.
Automatic Discovery
Section titled “Automatic Discovery”Karyam automatically discovers OAuth configuration from the MCP Server or identity provider.
This is the recommended option whenever supported.
Typical use cases include:
- SaaS platforms
- Public cloud providers
- Standard OAuth providers
Example:
Authentication Type:OAuth 2.0
OAuth Mode:Automatic DiscoveryManual Discovery
Section titled “Manual Discovery”Some enterprise environments use custom identity providers or internal OAuth infrastructure.
Manual Discovery allows explicit configuration of OAuth endpoints.
Typical use cases include:
- Internal identity providers
- Enterprise SSO platforms
- Private deployments
Example:
Authentication Type:OAuth 2.0
OAuth Mode:Manual DiscoveryRequest Headers
Section titled “Request Headers”Additional request headers can be attached to every request sent to the MCP Server.
Common examples include:
| Header | Purpose |
|---|---|
| Authorization | API authentication |
| X-API-Key | API key authentication |
| X-Tenant-ID | Tenant isolation |
| X-Environment | Environment routing |
Example:
| Key | Value |
|---|---|
| Authorization | Bearer **** |
| X-Tenant-ID | production |
Encrypted Headers
Section titled “Encrypted Headers”Sensitive values can be marked for encryption before storage.
Examples include:
- API Keys
- Access Tokens
- Client Secrets
- Internal Authentication Headers
Encrypted values are:
- Securely stored
- Permanently masked after submission
- Never displayed again in the user interface
Example:
AuthorizationBearer ********☑ EncryptImportant Security Behavior
Section titled “Important Security Behavior”Once an encrypted value has been saved:
- It cannot be viewed.
- It cannot be recovered.
- It cannot be exported.
To update an encrypted value:
- Enter a new value.
- Save the configuration again.
This behavior reduces accidental credential exposure.
Recommended Authentication Strategy
Section titled “Recommended Authentication Strategy”| Environment | Recommendation |
|---|---|
| Development | None |
| Internal Services | Encrypted Headers |
| SaaS Platforms | OAuth 2.0 |
| Enterprise Systems | OAuth 2.0 |
| Production Workloads | OAuth 2.0 + Encrypted Headers |
Example Configurations
Section titled “Example Configurations”Public MCP Server
Section titled “Public MCP Server”Authentication:NoneGitHub MCP Server
Section titled “GitHub MCP Server”Authentication:OAuth 2.0
Mode:Automatic DiscoveryInternal Enterprise API
Section titled “Internal Enterprise API”Authentication:None
Headers:Authorization: Bearer ********X-Tenant-ID: production
Encrypt:EnabledAuthentication Lifecycle
Section titled “Authentication Lifecycle”Karyam ↓Authenticate ↓MCP Server ↓Access Granted ↓Discover Tools ↓Execute ToolsAuthentication occurs before tool discovery and execution.
Security Best Practices
Section titled “Security Best Practices”Prefer OAuth
Section titled “Prefer OAuth”OAuth should be used whenever supported.
Encrypt Sensitive Values
Section titled “Encrypt Sensitive Values”Always encrypt:
- API Keys
- Access Tokens
- Secrets
- Internal Credentials
Use Least Privilege
Section titled “Use Least Privilege”Grant only the permissions required by the MCP Server.
Example:
Repository Read Accessinstead of:
Full Organization AccessRotate Credentials Regularly
Section titled “Rotate Credentials Regularly”Regular credential rotation reduces risk and improves compliance.
Separate Environments
Section titled “Separate Environments”Use separate credentials for:
- Development
- Staging
- Production
Observability
Section titled “Observability”Authentication events are recorded as part of MCP operations.
Examples include:
- Connection attempts
- Authentication failures
- Token expiration
- Authorization errors
This helps diagnose integration issues quickly.
Troubleshooting
Section titled “Troubleshooting”Authentication Failed
Section titled “Authentication Failed”Verify:
- Access tokens
- OAuth configuration
- Header values
- Credential permissions
OAuth Discovery Failed
Section titled “OAuth Discovery Failed”Verify:
- Discovery endpoints
- Network connectivity
- Identity provider configuration
Access Denied
Section titled “Access Denied”Verify:
- Account permissions
- Scope configuration
- Role assignments
Next Steps
Section titled “Next Steps”Continue with:
➡️ Server Discovery
Learn how Karyam automatically discovers MCP tools and capabilities after authentication succeeds.
