Creating MCP Client authorized apps

Before you create an MCP Client authorized app, ensure that:

  • You are assigned the IONAPI-Administrator role.
  • The EnableIONAPIMCPClient feature flag is enabled. This feature flag is enabled by default.
  • At least one MCP Server endpoint is available.
  • A Target Endpoint Description is specified for each MCP Server endpoint that you want to make available to the client.

MCP Client authorized apps enable external MCP tools to authenticate with API Gateway and access selected MCP Servers. Access is governed by the model described in Authorization and security model.

  1. Select App Menu > API Gateway > Authorized Apps.
  2. Select Add New Authorized App.
  3. Select MCP Client as the application type.
  4. Specify this information:
    Description
    Specify a name for the client. For example, Kiro - Engineering Team.
    Redirect URLs
    Specify the OAuth callback URLs for the MCP client. You can specify up to 10 redirect URLs.
    OAuth 2.0 Access Token TTL
    Specify the token lifetime for the client.
    Issue Refresh Tokens
    Select this option to issue refresh tokens for extended sessions.
  5. In the MCP Server Access section, select the MCP Servers that the client can access.
    • Use the scrollable selection table to select individual MCP Servers. You can select up to 10 MCP Servers for each MCP Client authorized app.
    • Use the column filters to filter by MCP Server name or endpoint URI.
  6. Select Save.

A client ID is generated in this format:

TENANT~<generated_key>

The MCP Client is an OAuth 2.1 public client and does not have a client secret.

An MCP Client configuration snippet is generated automatically based on the selected MCP Servers. Select Copy to copy the configuration to the clipboard.

The generated configuration uses the standard MCP client JSON format:

{
				"mcpServers": {
				"infor-m3-api": {
				"type": "http",
				"url": "https://{gateway-host}/ionapi/{tenant}/M3/mcp/",
				"oauth": {
				"clientId": "MYTENANT~EbTQ-u7A7OfTqrGMlrtVK-7wBeddA5qUWw7OrroXY7g"
				}
				},
				"infor-datalake": {
				"type": "http",
				"url": "https://{gateway-host}/ionapi/{tenant}/DataFabric/query/",
				"oauth": {
				"clientId": "MYTENANT~EbTQ-u7A7OfTqrGMlrtVK-7wBeddA5qUWw7OrroXY7g"
				}
				}
				}
				}
  • type: Always http for API Gateway MCP Servers.
  • url: The full proxy URL for the MCP endpoint.
  • oauth.clientId: The generated client ID used for authentication.