Connecting external MCP Clients
Any OAuth 2.1-compatible MCP Client can connect to MCP Servers through API Gateway. The authentication flow is the same for all clients, but the configuration method depends on the client.
Before you configure a client, create an MCP Client authorized app as described in Creating MCP Client authorized apps.
Setting up Kiro
Use the configuration generated for the MCP Client authorized app to connect Kiro to the selected MCP Servers.
When you create the authorized app, specify the redirect URL provided during Kiro setup. The URL is typically in this format:
http://localhost:{port}/callback
The MCP tools are available in your Kiro session.
Setting up Claude Desktop
Use the configuration generated for the MCP Client authorized app to connect Claude Desktop to the selected MCP Servers.
When you create the authorized app, specify a redirect URL in this format:
http://127.0.0.1:{port}/oauth/callback
Claude Desktop can access the MCP Servers selected for the authorized app.
Setting up other MCP Clients
Other OAuth 2.1-compatible MCP Clients, including Cursor and custom applications, can connect to MCP Servers through API Gateway.
The client must support OAuth 2.1 with PKCE, Protected Resource Metadata discovery, and standard MCP HTTP transport.
Setting up Cursor
Use the configuration generated for the MCP Client authorized app and adapt it to the MCP configuration format supported by Cursor.
Cursor can access the MCP Servers selected for the authorized app.
Setting up custom OAuth 2.1-compatible MCP Clients
A custom MCP Client can connect to API Gateway when it supports these requirements:
- OAuth 2.1 with PKCE by using the authorization code flow as a public client
- Protected Resource Metadata discovery through
.well-known/oauth-protected-resource - Standard MCP HTTP transport
The custom client can discover the authorization server, authenticate users, and access the MCP Servers selected for the authorized app.