---
title: "MCP OAuth authorization"
canonical: "https://canmyagentuse.com/features/mcp-oauth"
contentKind: "feature"
locale: "en"
description: "Complete the MCP authorization flow for protected remote servers. Compatibility evidence is tracked independently from other MCP capabilities."
llmSummary: "MCP OAuth authorization is an atomic MCP capability. Support for another MCP primitive does not imply this capability."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["interfaces","mcp"]
---

# MCP OAuth authorization

MCP OAuth authorization is an atomic MCP capability. Support for another MCP primitive does not imply this capability.

- HTML: https://canmyagentuse.com/features/mcp-oauth
- JSON: https://canmyagentuse.com/api/v1/features/mcp-oauth.json
- Markdown: https://canmyagentuse.com/features/mcp-oauth.md

Terminology basis: **MCP 2026-07-28** — https://modelcontextprotocol.io/specification/2026-07-28.

## Current support at a glance

MCP OAuth authorization: 5 supported, 1 partial, 0 unsupported, 25 unreviewed across 31 cataloged products.

- Reviewed current products: 6 of 31
- Supported: 5
- Partial: 1
- Unsupported: 0
- Unreviewed: 25
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

Complete the MCP authorization flow for protected remote servers.

This row remains unknown for a product until exact, dated evidence covers this capability rather than MCP generally.

## Catalog context

- Category: [interfaces](/categories/interfaces.md)
- Specification: [mcp](/specs/mcp.md) — revision 2026-07-28
- Aliases: MCP OAuth
- Family: [Model Context Protocol](/features/mcp.md)
- Siblings: [MCP Apps](/features/mcp-apps.md), [MCP cancellation](/features/mcp-cancellation.md), [MCP client role](/features/mcp-client-role.md), [MCP elicitation](/features/mcp-elicitation.md), [MCP legacy HTTP and SSE](/features/mcp-legacy-sse.md), [MCP list-changed notifications](/features/mcp-list-changed.md), [MCP logging](/features/mcp-logging.md), [MCP progress notifications](/features/mcp-progress.md), [MCP prompt-list notifications](/features/mcp-prompts-list-changed.md), [MCP prompts](/features/mcp-prompts.md), [MCP Registry metadata](/features/mcp-registry.md), [MCP resource subscriptions](/features/mcp-resource-subscriptions.md), [MCP resources](/features/mcp-resources.md), [MCP revision compatibility](/features/mcp-revision.md), [MCP roots](/features/mcp-roots.md), [MCP sampling](/features/mcp-sampling.md), [MCP server instructions](/features/mcp-server-instructions.md), [MCP server role](/features/mcp-server-role.md), [MCP stdio transport](/features/mcp-stdio.md), [MCP Streamable HTTP](/features/mcp-streamable-http.md), [MCP task listing](/features/mcp-task-listing.md), [MCP tasks](/features/mcp-tasks.md), [MCP tools](/features/mcp-tools.md)

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Unknown**

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Supported**
  - Target: dated-documentation — current Cursor MCP documentation observed 2026-08-28; observed 2026-08-28
  - Environment: local-default
  - Constraint (auth): remote servers may use dynamic registration or configured static credentials, and redirect URLs differ between web/agents and desktop surfaces
  - Evidence: [Cursor — Model Context Protocol](https://prod.cursor.com/docs/mcp) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: Cursor documents OAuth for remote MCP servers, dynamic or static client registration, fixed redirect URLs, and CLI login with automatic callback handling.
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Unknown**
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Supported**
  - Target: dated-documentation — current Zed MCP documentation observed 2026-08-28; observed 2026-08-28
  - Environment: local-default
  - Constraint (auth): automatic OAuth prompting applies when a remote server has no configured Authorization header
  - Evidence: [Zed — Model Context Protocol](https://zed.dev/docs/ai/mcp) — documented; observed 2026-08-28
  - Qualification note 6: Evidence checked 2026-08-28: Zed documents prompting the user through the standard MCP OAuth flow when a remote server has no configured Authorization header.
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Partial**
  - Target: dated-documentation — Continue source commit 5522c6f44ca0 observed 2026-08-28; observed 2026-08-28
  - Environment: local-default
  - Constraint (transport): the reviewed desktop connection path limits native MCP OAuth handling to legacy SSE servers
  - Constraint (auth): a browser callback is required; API keys and configured headers are separate authentication paths
  - Evidence: [Continue source — MCP OAuth client at 5522c6f](https://github.com/continuedev/continue/blob/5522c6f44ca0ac3528b37244818fbfa39b5af470/core/context/mcp/MCPOauth.ts) — documented; observed 2026-08-28
  - Evidence: [Continue source — MCP desktop client at 5522c6f](https://github.com/continuedev/continue/blob/5522c6f44ca0ac3528b37244818fbfa39b5af470/core/context/mcp/MCPConnection.ts) — documented; observed 2026-08-28
  - Qualification note 5: Evidence checked 2026-08-28: Continue's pinned desktop implementation includes the MCP OAuth authorization-code flow, but its connection path states that native OAuth is currently supported only for the legacy SSE transport.
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Supported**
  - Target: dated-documentation — Cline source commit 27350f243c2a observed 2026-08-28; observed 2026-08-28
  - Environment: local-default
  - Constraint (auth): browser authorization requires a working local callback path; manually configured authorization headers remain a separate option
  - Evidence: [Cline source — MCP OAuth manager at 27350f2](https://github.com/cline/cline/blob/27350f243c2a31c97b4e38fa700e009a2f61adae/apps/vscode/src/services/mcp/McpOAuthManager.ts) — documented; observed 2026-08-28
  - Evidence: [Cline source — MCP desktop client at 27350f2](https://github.com/cline/cline/blob/27350f243c2a31c97b4e38fa700e009a2f61adae/apps/vscode/src/services/mcp/McpHub.ts) — documented; observed 2026-08-28
  - Qualification note 4: Evidence checked 2026-08-28: Cline's pinned desktop implementation performs MCP OAuth discovery, client registration, browser authorization, callback validation, code exchange, token storage, and refresh for remote SSE and Streamable HTTP servers.
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Supported**
  - Target: dated-documentation — current Claude Code MCP documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (auth): OAuth applies to HTTP servers and requires a server-compatible redirect and client-registration flow
  - Evidence: [Anthropic — Connect Claude Code to tools via MCP](https://code.claude.com/docs/en/mcp) — documented; observed 2026-08-28
  - Qualification note 1: Evidence checked 2026-08-28: Claude Code documents browser-based OAuth for remote HTTP MCP servers, secure token storage and refresh, revocation, callback recovery, and fixed callback-port or preconfigured-client options.
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Unknown**
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Supported**
  - Target: dated-documentation — Gemini CLI MCP documentation updated 2026-06-18; observed 2026-08-28
  - Environment: local-default
  - Constraint (auth): browser-based OAuth requires local callback access; headless, remote SSH, and container environments need an alternative authentication arrangement
  - Evidence: [Google — MCP servers with Gemini CLI](https://geminicli.com/docs/tools/mcp-server/) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Gemini CLI documents OAuth 2.0 for remote SSE and HTTP MCP servers, automatic discovery, browser authorization, token storage and refresh, and `/mcp auth` management.
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
