Authentication

Auth0

Connect Auth0 OAuth, register MCP clients, and use ctx.user in tools.

Use this when Auth0 is your authorization server. MCP clients register directly with Auth0 and send Auth0 access tokens to your MCP server.

Configure Auth0

In the Auth0 dashboard:

  1. Create an API with an identifier you will use as the token audience (for example https://mcp.example.com/mcp)
  2. Enable Dynamic Client Registration for that API if required by your tenant
  3. Note your tenant domain (for example your-tenant.us.auth0.com)

The API identifier should match your public MCP URL or the resource you configure in bitmcp.

Set environment variables

AUTH0_DOMAIN=your-tenant.us.auth0.com
AUTH0_AUDIENCE=https://mcp.example.com/mcp

AUTH0_AUDIENCE is the OAuth resource when you do not pass resource in plugin options. Shared production vars: Installation → Environment variables.

Configure bitmcp

bitmcp.config.ts
import { defineConfig } from "bitmcp";
import { auth0 } from "bitmcp/oauth/auth0";

export default defineConfig({
  http: {
    path: "/mcp",
    allowedHosts: ["mcp.example.com"],
  },
  auth: auth0(),
});

Or inline:

bitmcp.config.ts
auth: auth0({
  domain: "https://your-tenant.us.auth0.com",
  resource: "https://mcp.example.com/mcp",
}),

Use ctx.user in tools

get-posts/tool.ts
export default defineTool({
  description: "Get recent blog posts for the signed-in user",
  async execute(_input, ctx) {
    return {
      id: ctx.user!.id,
      email: ctx.user!.email,
      roles: ctx.user!.roles,
      posts: [],
    };
  },
});

Auth0 roles from the token are available on ctx.user.roles when Auth0 includes them in the access token.

Verify

  1. Start the server with pnpm dev or pnpm start
  2. Connect from an OAuth-capable MCP client
  3. Complete Auth0 login and client registration
  4. Call a tool and confirm ctx.user is populated
  5. Call /mcp without a token and confirm 401

Options

auth0(options?: {
  domain?: URL | string;
  resource?: URL | string;
  requiredScopes?: string[];
  scopesSupported?: string[];
  resourceName?: string;
})
VariablePurpose
AUTH0_DOMAINAuth0 tenant domain
AUTH0_AUDIENCEToken audience and default OAuth resource

MCP_URL: Installation → Environment variables.

ctx.user includes the same base fields as Supabase (id, email, name) plus nickname, picture, emailVerified, updatedAt, and roles.