Skip to main content
GET
Start (or short-circuit) the auth flow for an MCP server

Authorizations

Authorization
string
header
required

Caller credential (Authorization: Bearer <token>). Required on protected routes when auth is enabled. Browser sessions may use the HttpOnly id_token or accessToken cookie instead.

Path Parameters

name
string
required

MCP server name.

Minimum string length: 1

Query Parameters

return_to
string

Same-origin path to land in the browser after consent.

Response

Either already authenticated, or an authorization URL to redirect to.

Current auth state.

status
enum<string>
required

Current auth state for this MCP server.

Available options:
authenticated,
auth_required,
not_required
authorization_url
string<uri>

When auth is required, this contains the URL to redirect the user to for authorization.