Two ways to use MCP Auth
If you are missing a catalog MCP server you can request it.
How to use it
Catalog MCP servers
-
Create the integration
In the Nango UI: Integrations β Configure New Integration β choose the MCP provider (e.g. HubSpot (MCP), Notion MCP).
Some providers, for example HubSpot MCP, require you to register an MCP auth app and add Client ID and Client Secret in Nango. But most support dynamic client registrations: You can just enable them on Nango, and Nango registers a client for you in the background.For agents
Create the integration with the API. MCP providers use theMCP_OAUTH2credentials type. Nango supports three client registration modes, set per provider in the catalog:Read it back β Get an integration with- cURL (static β client registered with the provider)
- cURL (dynamic or cimd)
?include=credentialsto see the storedclient_id/client_secret/scopes(requires theenvironment:integrations:read_credentialsscope):Fordynamicandcimdproviders,client_secretandscopescan come back empty ("") ornullright after creation β the MCP serverβs registration response doesnβt always issue a client secret (a public-client registration is common for DCR), and scopes are only set when you explicitly configure them. Thatβs expected, not a sign the registration failed. Scopes can be set or changed via the update endpoint in any mode, includingdynamicandcimdβ onlyclient_id/client_secretare restricted tostaticproviders.List all integrations works the same as for any other provider:Update β rotate credentials or change scopes with the sameMCP_OAUTH2credentials shape.client_id/client_secretcan only be set forstaticproviders; Nango rejects the request if you try to set them on adynamicorcimdintegration, since it manages those itself:Delete β same as any other integration:For all fields and response shapes, see Create, Get, List, Update, and Delete an integration. -
Run the same auth flow as standard OAuth
- Backend: create a Connect session with
allowed_integrations: ['<integration-id>'](e.g.hubspot-mcp,notion-mcp). - Frontend: open the Connect UI with the session token.
- Backend: persist the connection ID from the auth webhook or Connect UI callback.
- Backend: create a Connect session with
-
Call the MCP server
Use the storedconnection_idand integration id (e.g.hubspot-mcp) with the Proxy API (JSON-RPCtools/call, etc.).
Generic MCP Server OAuth2
-
Create a generic MCP integration
Integrations β Configure New Integration β MCP Server OAuth2 (Generic). Optionally set OAuth Client Name, URI, and Logo URI (used in dynamic client registration with the MCP server). -
Same Connect session + Connect UI flow
As above: backend creates a session withallowed_integrations: ['mcp-generic'](or your custom integration id), frontend opens Connect UI with that token, backend stores the connection ID. -
End user supplies the MCP server URL
When the user starts the connection, the Connect UI prompts for MCP Server URL (e.g.https://mcp.notion.com/mcp). Nango automatically discovers the OAuth endpoints from the server and walks the user through the OAuth connection flow. -
Call the MCP server
Same as pre-built: use the connection with the Proxy API. The connection is tied to the MCP server URL the user entered.
Our generic MCP provider currently only works with MCP servers that support automatic client registration (DCR, or CIMD).
End user experience
-
Catalog MCP servers
User sees a list of supported MCP servers in your app β clicks connect β is redirected to the providerβs OAuth page (e.g. HubSpot or Notion) β signs in and approves β connection is created in Nango -
MCP Generic
User clicks connect β sees a form asking for the MCP Server URL β submits β is redirected to that MCP serverβs OAuth page β signs in and approves β connection is created in Nango