- The first time a person’s request needs the MCP connector, the chat shows a Sign in to card for it. They click it and sign in with your identity provider (no password if they already signed in to xpander through it).
- xpander keeps that person’s token in the install’s vault and refreshes it.
- Every call carries
Authorization: Bearer <their token>. The MCP connector checks it and answers as that person.
Set it up
1. Turn it on (self-hosted).client-auth brokers the sign-in from its published origin. Empty, the default, turns MCP OAuth off.
https://client-auth.<domain>/mcp_auth/*, scopes openid profile email offline_access.
3. Make the MCP connector accept the token. Publish your identity provider’s endpoints at /.well-known/oauth-authorization-server on the MCP connector’s own origin (xpander reads it first and requests exactly its scopes_supported, so list only your client’s scopes). Answer a missing or bad token with 401. On every call, verify the token and act as the person in it:

Add server with OAuth2. Shown with sample data.

Add skill lists the organization entry. Shown with sample data.
What two people see
Alice and Bob ask the same agent “What equipment do I have?” for the first time. Each signs in once, then gets only their own equipment.
Alice's first prompt: sign in once. Shown with sample data.

Alice gets her equipment. Shown with sample data.

Bob's first prompt on the same agent: his own sign-in. Shown with sample data.

Bob gets his equipment, not Alice's. Shown with sample data.
CLIENT_AUTH_EXTERNAL_URL is empty. An invalid redirect URI at the identity provider means the /mcp_auth/* callback is not registered. invalid_scope means the MCP connector’s metadata lists a scope your client does not have.
