{"repo":"localden/remote-auth-mcp-apim-py","free":true,"listed":false,"github":"https://github.com/localden/remote-auth-mcp-apim-py","clone":"git clone https://github.com/localden/remote-auth-mcp-apim-py.git","description":"Remote MCP server with auth gated by Azure API Management","language":"Bicep","stars":31,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"🤫 Authenticated Remote MCP Server This sample shows how to deploy an Entra ID-protected MCP server on Azure. The sample also uses an authorization pattern where the client acquires a token for the MCP server first, and then uses on-behalf-of flow to exchange it for a token that can be used with Microsoft Graph. It does all this in an entirely secretless manner too. ⚠️ Important: Experimental Implementation [!IMPORTANT] This is an experimental implementation and should NOT be used in production scenarios. This sample demonstrates how to build a protected MCP server with Entra ID by implementing OAuth 2.0 Dynamic Client Registration and PKCE flow patterns that work around current gaps in Entra ID's native support for these standards. While it showcases the technical possibilities, it's intended for educational and proof-of-concept purposes only. For production scenarios, consider using established authentication patterns with pre-registered applications and standard OAuth flows. What it uses - ⚡ Azure Functions - 🕸️ Azure API Management - 💪 Bicep - 🐍 Python - 🚀 Azure Developer CLI [!NOTE] You can use the Model Context Protocol Inspector or Visual Studio Code to test this MCP server. How the Authorization Flow Works This implementation uses a sophisticated OAuth 2.0 flow with PKCE (Proof Key for Code Exchange) to securely authenticate MCP clients. Here's how it all fits together: Security Features & Cookies Used This implementation uses several security mechanisms and cooki","default_branch":null,"files":null,"tree":[],"storefront":"/r/localden","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/localden/remote-auth-mcp-apim-py/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}