# WorkOS AuthKit MCP

> A spec-compliant OAuth 2.1 authorization server for MCP that provides SSO-integrated access, scoped tokens, PKCE, consent flows, and client registration (supporting both CIMD and DCR) for enterprise MCP server deployments.

- **URL:** https://workos.com/docs/mcp
- **Category:** Developer Tools "Developer Tools"amp; IDE MCP Servers
- **Tags:** Oauth, Enterprise Auth, Mcp
- **Updated:** 2026-04-23 14:13
- **Canonical page:** https://mcpserver.ever.works/items/workos-authkit-mcp

## Details

## Overview

WorkOS AuthKit acts as a spec-compliant OAuth 2.1 authorization server for MCP. The MCP server acts as the Resource Server; AuthKit handles authorization, token issuance, consent screens, and client registration.

## Features

- **SSO-Integrated Access**: IT teams can manage MCP access through existing identity providers
- **OAuth 2.1 Compliance**: Scoped tokens, PKCE, and consent flows following the MCP specification
- **Client Registration Support**: Both Client ID Metadata Documents (CIMD, current spec default) and Dynamic Client Registration (DCR, for backwards compatibility)
- **Minimal Integration**: Point server's protected resource metadata at an AuthKit domain and verify JWTs on incoming requests

## Deployment Options

- **AuthKit**: Full authorization server handling OAuth flows, consent, and token issuance
- **Standalone Connect**: Runs as middleware for MCP OAuth flows without requiring a migration. Users authenticate with your existing system; AuthKit handles only the OAuth authorization and token issuance that MCP clients need

## Pricing

See WorkOS pricing documentation for details.

---

_This Markdown mirror is generated by Ever Works for AI agents. The canonical HTML page is at https://mcpserver.ever.works/items/workos-authkit-mcp._
