Set up Auth0 MCP Server
Install Auth0 MCP Server with verified links, sign in via OAuth, limit permissions with --read-only and --tools, and start safely against a test tenant.
- Skill Road
- Set up Auth0 MCP Server
Published on 18.09.2026
Auth0 MCP Server connects an AI client to the Management APIs of an Auth0 tenant. With it, an agent can create applications, deploy Auth0 Actions, manage APIs, and search sign-in logs. The server is beta software; use it against a test or development tenant first.
Prerequisites
You need Node.js 18 or newer, an Auth0 account with sufficient management permissions, and an MCP-capable client such as Claude Code, Cursor, or VS Code. Check the Node version with node --version and activate a suitable one through nvm if needed.
Set up the server
For Claude Desktop, npx @auth0/auth0-mcp-server init is enough. For other clients, append the target client, for example npx @auth0/auth0-mcp-server init --client claude-code, --client cursor, --client vscode, --client windsurf, --client gemini, or --client codex. The command writes the server into the client's configuration.
Sign in
On first start the browser opens for the OAuth 2.0 device authorization flow. Sign in to Auth0 and confirm the requested permissions. The server stores the credentials in your operating system's keychain; you can verify this in your keychain manager. For private cloud tenants, client credentials are available instead.
Limit permissions
Start with npx @auth0/auth0-mcp-server init --read-only so that only read tools are available. Use --tools to narrow further, for example --tools 'auth0_list_*,auth0_get_*' for read-only access or --tools 'auth0_list_applications,auth0_get_application' for a single use case.
Start safely
Begin with questions such as "Show me all applications" or "Search the logs for failed sign-ins". Only once the connection works and you have reviewed the output should you enable write tools – update an application, deploy an Action, create a client grant. Keep the permissions of the signed-in account as narrow as possible and separate test tenants from production tenants.
Frequently asked questions
Is the Auth0 MCP Server official?
Yes. The server is maintained by Auth0 in the auth0/auth0-mcp-server repository and is described in the Auth0 documentation as the "Auth0 Model Context Protocol (MCP) Server". The npm package is named @auth0/auth0-mcp-server and is licensed under MIT.
Can I use the server in production?
Auth0 labels the server as beta and advises against use in production or for critical workloads. Running it against a test or development tenant is the sensible choice until Auth0 lifts the beta status.
How do I stop an agent from making unwanted changes?
Start with --read-only so that only read tools are available. With --tools and a pattern such as auth0_list_*,auth0_get_* you narrow the scope further and enable write tools only deliberately.
Where are my Auth0 credentials stored?
After the OAuth sign-in the server stores the credentials in your operating system keychain, not as plain text in a configuration file. For private cloud tenants the server additionally supports client credentials.
Which clients are supported?
Per the repository: Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, the Gemini CLI, and the Codex CLI. Other MCP-capable clients can be added through a manual configuration using the command npx -y @auth0/auth0-mcp-server run.
Which Node version do I need?
Node.js 18 or newer. Check the version with node --version; with nvm you can quickly activate a suitable one via nvm install 18 and nvm use 18.