Skip to main content
Why: give a shared agent access to an internal system without a shared service account. Each person signs in once; from then on the agent calls your MCP connector with that person’s own token, and your system decides what they may see and do. Two people asking the same agent get different, correct answers, and every call is attributable to the person who made it. How it works:
  1. The first time a person’s request needs the MCP connector, the chat shows a Sign in to card for it. They click it and sign in with your identity provider (no password if they already signed in to xpander through it).
  2. xpander keeps that person’s token in the install’s vault and refreshes it.
  3. Every call carries Authorization: Bearer <their token>. The MCP connector checks it and answers as that person.

Set it up

1. Turn it on (self-hosted). client-auth brokers the sign-in from its published origin. Empty, the default, turns MCP OAuth off.
2. Create a client at your identity provider. Confidential, authorization code flow, redirect URI https://client-auth.<domain>/mcp_auth/*, scopes openid profile email offline_access. 3. Make the MCP connector accept the token. Publish your identity provider’s endpoints at /.well-known/oauth-authorization-server on the MCP connector’s own origin (xpander reads it first and requests exactly its scopes_supported, so list only your client’s scopes). Answer a missing or bad token with 401. On every call, verify the token and act as the person in it:
4. Register it for the organization. Settings > Skills, the list of MCP servers, Add server: Shared with Organization, the server URL, Authentication OAuth2, the client’s Client ID and Client secret.
Add server form with Name Acme Inventory, Shared with Organization, Remote, Server URL, HTTP, Authentication OAuth2, Client ID, a masked Client secret and the Redirect URL

Add server with OAuth2. Shown with sample data.

5. Attach it to a shared agent. In the agent’s settings, Add skill, pick the entry, and give the agent Org-wide access.
Add a skill panel searching inventory, listing Acme Inventory of type MCP

Add skill lists the organization entry. Shown with sample data.

What two people see

Alice and Bob ask the same agent “What equipment do I have?” for the first time. Each signs in once, then gets only their own equipment.
Acme IT Assistant chat as Alice with a Sign in to Acme Inventory card

Alice's first prompt: sign in once. Shown with sample data.

Acme IT Assistant answering Alice with the three items assigned to her

Alice gets her equipment. Shown with sample data.

Acme IT Assistant chat as Bob with a Sign in to Acme Inventory card

Bob's first prompt on the same agent: his own sign-in. Shown with sample data.

Acme IT Assistant answering Bob with the items assigned to him

Bob gets his equipment, not Alice's. Shown with sample data.

If it fails: “MCP OAuth is not available on this deployment.” means CLIENT_AUTH_EXTERNAL_URL is empty. An invalid redirect URI at the identity provider means the /mcp_auth/* callback is not registered. invalid_scope means the MCP connector’s metadata lists a scope your client does not have.