This article is written by the team that builds Casdoor, so we are not neutral, and we say where we think Casdoor fits and where it doesn't. Facts about other products come from their own websites as of October 8, 2026 (listed under Sources) and may have changed. Spotted something out of date? Tell us.
Remote MCP servers let Claude, ChatGPT, Cursor and other AI clients call your tools and data. The MCP specification says how they should be protected: the MCP server is an OAuth resource server, and an authorization server issues the tokens. Most teams don't want to write that authorization server, so they use an identity provider.
This list ranks the providers that support MCP authorization today, judged against the current spec (2026-07-28).
What an MCP authorization server needs
- Authorization server metadata (RFC 8414) so clients can find the endpoints, and your MCP server publishes protected resource metadata (RFC 9728) that points to it.
- Client registration without a human in the loop. The spec now prefers Client ID Metadata Documents (CIMD), where the client's ID is an HTTPS URL to its metadata. Dynamic Client Registration (RFC 7591) is deprecated but still widely used by existing clients.
- OAuth 2.1 with PKCE and a consent screen the user can understand.
- Resource indicators (RFC 8707) so a token is only valid for one MCP server.
- Ideally, token exchange (RFC 8693) for an agent acting on a user's behalf, and per-tool permissions.
At a glance
| # | Provider | CIMD | DCR | Self-host | Open source | Free to start |
|---|---|---|---|---|---|---|
| 1 | WorkOS AuthKit | Yes | Yes | No | No | Up to 1M MAU |
| 2 | Casdoor | Not yet | Yes | Yes | Yes (Apache-2.0) | Self-host, or Cloud trial credit |
| 3 | Auth0 | Yes | Yes | No | No | Free plan |
| 4 | Descope | Yes | Yes | No | No | 7,500 MAU |
| 5 | Keycloak | Experimental | Yes | Yes | Yes (Apache-2.0) | Self-host |
1. WorkOS AuthKit
WorkOS AuthKit was one of the first to ship MCP authorization and supports both CIMD and DCR (CIMD has to be switched on in the dashboard). AuthKit itself is free up to one million MAU, which makes it an easy default for a SaaS product exposing an MCP server.
Trade-offs: cloud only, and enterprise SSO and directory sync are billed per connection.
2. Casdoor
Casdoor is the best choice if you want to own your MCP authorization server. It is open source, so you can run it next to internal MCP servers that never touch the internet, or use Casdoor Cloud from $24.17/month billed yearly.
Casdoor implements Dynamic Client Registration, protected resource metadata for MCP servers it fronts, resource indicators, DPoP-bound tokens and token exchange. It goes beyond the spec with MCP-specific features: a registry of your MCP servers that syncs their tools, per-tool permissions so users approve only the tools an agent needs, and a network scan for MCP servers nobody registered. Agent sign-ins land in the same audit log as people.
Trade-offs: Client ID Metadata Documents are not supported yet, so Casdoor relies on DCR, which today's MCP clients still support as a fallback.
3. Auth0
Auth0's Auth for MCP became generally available in May 2026, with CIMD registration and on-behalf-of token exchange. If you already use Auth0 for your app, adding it to your MCP server is straightforward.
Trade-offs: pricing for AI agent features sits on top of Auth0's MAU-based plans, and it only runs in Okta's cloud.
4. Descope
Descope's Agentic Identity Hub gives MCP servers and agents their own control plane, with DCR and CIMD supported side by side. It is available on the free tier (7,500 MAU).
Trade-offs: cloud only; paid plans start at $249 per month.
5. Keycloak
Keycloak supports server metadata and DCR, which cover the 2025-03-26 MCP spec. CIMD and resource indicators are available as experimental features that you enable with startup flags.
Trade-offs: support for the newer MCP spec versions is still experimental, and you run it yourself.
Which one should you choose?
- Your MCP server is part of a SaaS product and you're happy in someone else's cloud: WorkOS or Auth0.
- Your MCP servers are internal, regulated or self-hosted, or you want per-tool permissions and an inventory of MCP servers: Casdoor.
- You already run Keycloak: try its experimental MCP support before adding another system.
To see the Casdoor flow end to end, read about identity for AI agents or start a free trial.
Sources
- MCP spec 2026-07-28: client registration
- WorkOS AuthKit for MCP
- WorkOS pricing
- Auth0: Auth for MCP generally available
- Descope: CIMD support
- Descope Agentic Identity Hub
- Keycloak as an MCP authorization server
- Casdoor on GitHub
Product names are trademarks of their respective owners.