Skip to content
Karyam

Authentication

Most MCP Servers expose capabilities that interact with sensitive systems and data.

Examples include:

  • Source code repositories
  • Internal APIs
  • Databases
  • Ticketing systems
  • Business applications

As a result, authentication is a critical part of any MCP integration.

Karyam provides secure mechanisms for authenticating with MCP Servers while ensuring credentials remain protected.


Karyam currently supports the following authentication methods:

  • No Authentication
  • OAuth 2.0
  • Custom Request Headers

Some MCP Servers operate in trusted environments and do not require authentication.

Examples include:

  • Local development servers
  • Internal test environments
  • Air-gapped deployments

Configuration:

Authentication Type:
None

OAuth 2.0 is the recommended authentication mechanism for production environments.

It provides:

  • Secure token exchange
  • Delegated authorization
  • Credential isolation
  • Revocable access

Karyam supports two OAuth modes.


Karyam automatically discovers OAuth configuration from the MCP Server or identity provider.

This is the recommended option whenever supported.

Typical use cases include:

  • SaaS platforms
  • Public cloud providers
  • Standard OAuth providers

Example:

Authentication Type:
OAuth 2.0
OAuth Mode:
Automatic Discovery

Some enterprise environments use custom identity providers or internal OAuth infrastructure.

Manual Discovery allows explicit configuration of OAuth endpoints.

Typical use cases include:

  • Internal identity providers
  • Enterprise SSO platforms
  • Private deployments

Example:

Authentication Type:
OAuth 2.0
OAuth Mode:
Manual Discovery

Additional request headers can be attached to every request sent to the MCP Server.

Common examples include:

Header Purpose
Authorization API authentication
X-API-Key API key authentication
X-Tenant-ID Tenant isolation
X-Environment Environment routing

Example:

Key Value
Authorization Bearer ****
X-Tenant-ID production

Sensitive values can be marked for encryption before storage.

Examples include:

  • API Keys
  • Access Tokens
  • Client Secrets
  • Internal Authentication Headers

Encrypted values are:

  • Securely stored
  • Permanently masked after submission
  • Never displayed again in the user interface

Example:

Authorization
Bearer ********
☑ Encrypt

Once an encrypted value has been saved:

  • It cannot be viewed.
  • It cannot be recovered.
  • It cannot be exported.

To update an encrypted value:

  1. Enter a new value.
  2. Save the configuration again.

This behavior reduces accidental credential exposure.


Environment Recommendation
Development None
Internal Services Encrypted Headers
SaaS Platforms OAuth 2.0
Enterprise Systems OAuth 2.0
Production Workloads OAuth 2.0 + Encrypted Headers

Authentication:
None

Authentication:
OAuth 2.0
Mode:
Automatic Discovery

Authentication:
None
Headers:
Authorization: Bearer ********
X-Tenant-ID: production
Encrypt:
Enabled

Karyam
↓
Authenticate
↓
MCP Server
↓
Access Granted
↓
Discover Tools
↓
Execute Tools

Authentication occurs before tool discovery and execution.


OAuth should be used whenever supported.


Always encrypt:

  • API Keys
  • Access Tokens
  • Secrets
  • Internal Credentials

Grant only the permissions required by the MCP Server.

Example:

Repository Read Access

instead of:

Full Organization Access

Regular credential rotation reduces risk and improves compliance.


Use separate credentials for:

  • Development
  • Staging
  • Production

Authentication events are recorded as part of MCP operations.

Examples include:

  • Connection attempts
  • Authentication failures
  • Token expiration
  • Authorization errors

This helps diagnose integration issues quickly.


Verify:

  • Access tokens
  • OAuth configuration
  • Header values
  • Credential permissions

Verify:

  • Discovery endpoints
  • Network connectivity
  • Identity provider configuration

Verify:

  • Account permissions
  • Scope configuration
  • Role assignments

Continue with:

➡️ Server Discovery

Learn how Karyam automatically discovers MCP tools and capabilities after authentication succeeds.