Skip to content

Introduce auth spec into Registry #751

Description

@tadasant

Requirements from @toby:

  • Goal is to allow private entries into an MCP registry
  • Users who auth into an MCP registry should be able to see different available MCP servers based on what permissions they have
  • Should be equal to (or at least similar) to how auth in the MCP spec works

Toby says Harald from VS Code and others can provide feedback, etc, to help nail down requirements here.

This would not be functionality we expose in the public registry - it'd just be a spec that downstream sub-registries can (optionally) adopt.

Activity

  1. domdomegg commented on Nov 7, 2025

    @domdomegg
    Member

    I've written up a proposal in #756 based on the MCP auth spec. It basically lets sub-registries work as OAuth 2.1 resource servers (same as MCP servers), so clients can reuse their existing auth code.

    Would be good to get feedback from registry implementors on whether this works for their needs.

  2. added a commit that references this issue on Nov 17, 2025
    32b37e7
  3. added a commit that references this issue on Nov 20, 2025
    d53da24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions