Blog · Top lists

Top 5 OAuth authorization servers for MCP servers and AI agents

Which identity providers can secure remote MCP servers under the 2026 MCP authorization spec: WorkOS, Casdoor, Auth0, Descope and Keycloak compared.

Casdoor Team · October 8, 2026 · 3 min read

This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.

Remote MCP servers let Claude, ChatGPT, Cursor and other AI clients call your tools and data. The MCP specification says how they should be protected: the MCP server is an OAuth resource server, and an authorization server issues the tokens. Most teams don't want to write that authorization server, so they use an identity provider.

This list ranks the providers that support MCP authorization today, judged against the current spec (2026-07-28).

What an MCP authorization server needs

  • Authorization server metadata (RFC 8414) so clients can find the endpoints, and your MCP server publishes protected resource metadata (RFC 9728) that points to it.
  • Client registration without a human in the loop. The spec now prefers Client ID Metadata Documents (CIMD), where the client's ID is an HTTPS URL to its metadata. Dynamic Client Registration (RFC 7591) is deprecated but still widely used by existing clients.
  • OAuth 2.1 with PKCE and a consent screen the user can understand.
  • Resource indicators (RFC 8707) so a token is only valid for one MCP server.
  • Ideally, token exchange (RFC 8693) for an agent acting on a user's behalf, and per-tool permissions.

At a glance

# Provider CIMD DCR Self-host Open source Free to start
1 WorkOS AuthKit Yes Yes No No Up to 1M MAU
2 Casdoor Not yet Yes Yes Yes (Apache-2.0) Self-host, or Cloud trial credit
3 Auth0 Yes Yes No No Free plan
4 Descope Yes Yes No No 7,500 MAU
5 Keycloak Experimental Yes Yes Yes (Apache-2.0) Self-host

1. WorkOS AuthKit

WorkOS AuthKit was one of the first to ship MCP authorization and supports both CIMD and DCR (CIMD has to be switched on in the dashboard). AuthKit itself is free up to one million MAU, which makes it an easy default for a SaaS product exposing an MCP server.

Trade-offs: cloud only, and enterprise SSO and directory sync are billed per connection.

2. Casdoor

Casdoor is the best choice if you want to own your MCP authorization server. It is open source, so you can run it next to internal MCP servers that never touch the internet, or use Casdoor Cloud from $24.17/month billed yearly.

Casdoor implements Dynamic Client Registration, protected resource metadata for MCP servers it fronts, resource indicators, DPoP-bound tokens and token exchange. It goes beyond the spec with MCP-specific features: a registry of your MCP servers that syncs their tools, per-tool permissions so users approve only the tools an agent needs, and a network scan for MCP servers nobody registered. Agent sign-ins land in the same audit log as people.

Trade-offs: Client ID Metadata Documents are not supported yet, so Casdoor relies on DCR, which today's MCP clients still support as a fallback.

3. Auth0

Auth0's Auth for MCP became generally available in May 2026, with CIMD registration and on-behalf-of token exchange. If you already use Auth0 for your app, adding it to your MCP server is straightforward.

Trade-offs: pricing for AI agent features sits on top of Auth0's MAU-based plans, and it only runs in Okta's cloud.

4. Descope

Descope's Agentic Identity Hub gives MCP servers and agents their own control plane, with DCR and CIMD supported side by side. It is available on the free tier (7,500 MAU).

Trade-offs: cloud only; paid plans start at $249 per month.

5. Keycloak

Keycloak supports server metadata and DCR, which cover the 2025-03-26 MCP spec. CIMD and resource indicators are available as experimental features that you enable with startup flags.

Trade-offs: support for the newer MCP spec versions is still experimental, and you run it yourself.

Which one should you choose?

  • Your MCP server is part of a SaaS product and you're happy in someone else's cloud: WorkOS or Auth0.
  • Your MCP servers are internal, regulated or self-hosted, or you want per-tool permissions and an inventory of MCP servers: Casdoor.
  • You already run Keycloak: try its experimental MCP support before adding another system.

To see the Casdoor flow end to end, read about identity for AI agents or start a free trial.