MCP verified user access configuration

MCP verified user access requires the following configuration:

  • Workato Identity access method with assigned end user groups.

  • End user tool connection with OAuth 2.0 authorization code grant.

Workato Identity configuration

Complete the following steps to configure Workato Identity for MCP verified user access:

MCP Workato Identity access method and end-user group configuration

Ensure that you have end-user group with assigned users in Workato Identity before following these steps.

Complete the following steps to set your MCP server access method to Workato Identity and add end-user groups:

1

Go to AI Hub and select the MCP servers tab.

2

Click the MCP server you plan to use.

3

Click the End user access tab.

4

Go to the Access Method section and ensure that Workato Identity is selected.

5

Click Add user groups.

Click Add user groupsClick Add user groups

6

Use the User groups drop-down menu to select the user groups you plan to provide with access to the MCP server.

7

Click Add.

Configure an OAuth 2.0 authorization code grant connection

The End user's connection option only supports OAuth 2.0 connections.

Complete the following steps to set up an OAuth 2.0 connection:

1

Go to AI Hub and select the MCP servers tab.

2

Click the MCP server you plan to use.

3

Select the tool you plan to use with the end user's connection. The recipe editor opens.

4

Click Edit.

5

Select the action step where you plan to add the connection.

6

Select End user's connection.

Select End user's connectionSelect End user's connection

7

Provide a name for your connection in the Name field.

Authorization code grant connection exampleAuthorization code grant connection example

8

Use the Location drop-down menu to select the project where you plan to store the connection.

9

Use the Authentication type drop-down menu to select Authorization code grant.

10

Enter your client ID in the Client ID field.

11

Enter your client secret in the Client secret field.

12

Provide your host or endpoint URL in the appropriate field. The required field name and value differ by application. For example, a Coupa connection requires the host URL in the Host field with the following URL format: https://your-instance-name.coupacloud.com.

13

Use the Scopes drop-down menu to select the scopes you plan to use for your connection.

14

Click Connect.

Last updated: