AI agents & MCP

Identity and access control for AI agents

AI agents now read your tickets, query your data and call your APIs. Casdoor gives every agent a verifiable identity and lets your users decide exactly what it may do, using the same OAuth standards the MCP specification is built on.

How an AI client gets access

  1. 1RFC 9728

    Discover

    The AI client calls your MCP server and finds Casdoor in its protected resource metadata.

  2. 2RFC 7591

    Register

    The client registers itself with Casdoor. No API keys to copy around.

  3. 3OAuth 2.1 + PKCE

    Consent

    The user signs in and approves only the tools and scopes the agent needs.

  4. 4RFC 8707 · DPoP

    Act

    The agent gets a short-lived token for that one server, bound to its key.

MCP server registry

List your MCP servers, sync their tools and decide which tools each application may call.

Find shadow MCP servers

Scan your internal network for MCP servers nobody registered, before an agent finds them.

Delegation, not impersonation

Token Exchange lets an agent act on a user's behalf with a narrower, traceable token.

Every action on record

Agent sign-ins and API calls land in the same audit trail as people, and can stream to your SIEM.

What's included

  • OAuth authorization server for MCP
  • Protected resource metadata (RFC 9728)
  • Dynamic client registration (RFC 7591)
  • Tokens for one server (RFC 8707)
  • Token Exchange (RFC 8693)
  • DPoP-bound tokens (RFC 9449)
  • Device login for CLIs (RFC 8628)
  • Per-tool permissions

Included in the free open-source edition and in every Casdoor Cloud plan.

GET mcp.acme.com/.well-known/oauth-protected-resource
{
  "resource": "https://mcp.acme.com",
  "authorization_servers": ["https://door.acme.com"],
  "scopes_supported": ["tickets:read", "tickets:write"],
  "bearer_methods_supported": ["header"]
}

// The MCP client finds Casdoor here, registers itself (RFC 7591)
// and asks for a token for https://mcp.acme.com (RFC 8707).

FAQ

Frequently asked questions

Can Casdoor secure AI agents and MCP servers?
Yes. Casdoor can act as the OAuth authorization server for your MCP servers: it publishes the metadata MCP clients look for, lets AI clients register themselves (RFC 7591), issues tokens scoped to one server (RFC 8707) and to the tools a user approved, and supports Token Exchange and DPoP.
Which AI clients work with it?
MCP clients that follow the MCP authorization specification, such as Claude, ChatGPT, Cursor, VS Code, as well as agents you build yourself.
Can Casdoor find MCP servers that nobody registered?
Yes. Casdoor can scan your internal network for MCP servers that are not in its registry, so you can bring them under control before an agent finds them.