Auth0 MCP Server
Official Auth0 MCP server: create applications, deploy Auth0 Actions, manage APIs, and search sign-in logs via natural language.
- Skill Road
- Auth0 MCP Server
Description
Auth0 MCP Server is the official Model Context Protocol server from Auth0, the identity and access service that has been part of Okta since 2021. The server connects AI agents and editors such as Claude Desktop, Claude Code, Cursor, VS Code, Windsurf, the Gemini CLI, or the Codex CLI to the Management APIs of an Auth0 tenant. With it, an agent can create applications, write and deploy Auth0 Actions, manage APIs (resource servers), and search sign-in logs through natural language, without opening the Auth0 dashboard. Source code and documentation are public: the repository at https://github.com/auth0/auth0-mcp-server, the starting point at https://auth0.com/docs/get-started/auth0-mcp-server. The npm package is named @auth0/auth0-mcp-server and was at version v0.1.0-beta.19 (released on 2026-08-13) under the MIT license when checked on 2026-09-08; the GitHub star count was 118. That number is a point-in-time snapshot of adoption, not a quality or security guarantee.
Beta status
Auth0 explicitly labels the server as beta software provided "AS IS" without warranties. Features and interfaces may change at any time, support during the beta period is limited, and Auth0 advises against use in production or for critical workloads. Anyone adopting the server should factor that into their planning and first run it against a test or development tenant.
What the server can do
According to the provider, the toolset covers the core administration tasks of an Auth0 tenant. For applications, an agent can list existing entries and search them by name, fetch details, create new applications, update existing ones, and write the generated credentials to a file in the project. For getting a project started there is an onboarding flow: the server creates a suitably configured application for the detected framework, writes the values into a .env file, and then returns the framework-specific quickstart including resolved callback URLs. The agent can further list, get, create, and update APIs (resource servers), create client grants between an application and an API, list, get, create, update, and deploy Auth0 Actions, and retrieve sign-in and error logs, including individual log entries. Newer versions add tools for Auth0 Forms: list, get, create, update, and publish.
Setup
The server runs locally as a stdio process and is started through npx. The prerequisites are Node.js 18 or newer, an Auth0 account with sufficient permissions, and an MCP-capable client. The command npx @auth0/auth0-mcp-server init configures the server for Claude Desktop; the --client flag targets Claude Code, Cursor, VS Code, Windsurf, Gemini, or Codex. On first start the browser opens for the OAuth 2.0 device authorization flow; after sign-in and consent, the credentials are stored in the operating system's keychain. For private cloud tenants the server additionally supports client credentials.
Scope access narrowly
Because a broadly permitted Auth0 tenant is sensitive, the server ships two restrictions. The --read-only flag allows only read tools, and --tools lets you specify by pattern exactly which tools are available, for example --tools 'auth0_list_*,auth0_get_*'. Auth0 recommends starting with these restrictions and enabling write tools only deliberately. An agent that may change an application or deploy an Action is making real changes to the sign-in behavior of an environment.
Cost and license
The MCP server itself is open source under the MIT license and free to use. Auth0 as a service has a free entry tier plus paid plans and enterprise tiers; the current terms are stated on Auth0's official pricing page. This entry deliberately avoids fixed amounts.
Who the server is for
Auth0 MCP Server makes sense for developers and platform teams that build Auth0 into projects and want to handle recurring tenant tasks – creating a new application, setting callback URLs, deploying an Action, searching login failures in the logs – from within their AI editor. For a one-time setup, the dashboard is enough. Before wider use, teams should test the server against a non-production tenant, keep the permissions of the signed-in account narrow, and start with --read-only.
Requirements
Node.js 18 or newer, an Auth0 account with sufficient management permissions, and an MCP-capable client; npx/npm for local operation.
Installation instructions
Set up with npx @auth0/auth0-mcp-server init for Claude Desktop; append --client claude-code|cursor|vscode|windsurf|gemini for other clients. Limit permissions with --read-only and --tools '<pattern>'.
npx @auth0/auth0-mcp-server init
Authentication
OAuth 2.0 device authorization flow in the browser; credentials are stored in the operating system keychain. Client credentials are additionally possible for private cloud tenants.
Required access permissions
The server acts with the permissions of the signed-in Auth0 account: applications, resource servers/APIs, client grants, Auth0 Actions, Forms, and sign-in and error logs. The scope can be restricted with --read-only and --tools.
Transmitted or stored data
Prompts and application, Action, and query parameters go to the Auth0 Management API; responses such as application details, Action code, configurations, and log entries return to the MCP client.
Security risks
A broadly permitted Auth0 account gives an agent write access to the sign-in of an entire environment – applications, Actions, and grants. The server is beta and not recommended for production. Run it against a test tenant first, start with --read-only, and keep the account permissions narrow.
License and costs
- License
- MIT
- Cost
- free
The MCP server is open source under the MIT license and free to use. Auth0 as a service has a free entry tier, paid plans, and enterprise tiers per Auth0's official pricing page.
Alternatives
Not recorded yet.
At a glance
- Provider
- Auth0
- Status
- Official server
- Deployment
- Local
- Current version
- v0.1.0-beta.19
- GitHub stars
- 122
- Last reviewed
- 08.09.2026
Repository and documentation
Categories
Supported clients
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026