Lesson 17 / 25

Remote Servers and Authorization

Connect to a remote HTTP server and understand why it needs real authentication.

OAuth for remote tools

A remote MCP server acts on your behalf in other systems, so it must know who is calling. The MCP specification uses OAuth 2.1 based authorization for HTTP servers: the host sends you through a sign-in, then presents a short-lived access token with each request. Never paste a long-lived password or API key into a shared server config.

Adding a remote server

Claude Code can register an HTTP server by URL. The sign-in step happens in the host, so your token is never typed into the config file.

claude mcp add --transport http issues https://mcp.example.com/mcp

Quick check: How should a host authenticate to a remote MCP server?

  • With an OAuth-based flow and short-lived tokens
  • By sending the user's email password
  • By skipping authentication
  • By hard-coding an admin key in the config
Answer

With an OAuth-based flow and short-lived tokens — Token-based authorization lets users grant limited access that can be revoked.