APS MCP Auth Examples
Reference MCP servers that integrate with Autodesk Platform Services, demonstrating various authentication combinations and exposing tools to list projects and folder contents via the Data Management API.
README
APS MCP Auth Examples
Reference implementations of MCP servers that integrate with Autodesk Platform Services, covering every combination of:
- How the server authenticates to APS
2LO- 2-legged OAuth, app-wide3LO- 3-legged OAuth, per-userPKCE- 3-legged OAuth for public clients, per-userSSA- Secure Service Account, non-human identity
- How MCP clients authenticate to the server
- not at all (STDIO)
- via an external identity provider
- via an OAuth proxy service
All HTTP-based examples target the 2026-07-28 MCP specification revision
via the split MCP TypeScript SDK v2
(@modelcontextprotocol/{server,express,node}), which requires MCP servers to
act as OAuth 2.1 resource servers backed by a dedicated authorization server,
and prefers Client ID Metadata Documents (CIMD) over Dynamic Client
Registration for identifying MCP clients.
Every example exposes the same MCP tools, implemented once in shared/ and
reused everywhere: list-projects (hubs + projects, via the Data Management
API) and list-contents (a project's top-level folders, or a specific folder's
contents).
The examples
| Folder | MCP-client auth | What it demonstrates |
|---|---|---|
aps-mcp-server-local |
none (STDIO) | The simplest possible setup — a locally spawned process, no MCP-layer auth at all. |
aps-mcp-server-remote-auth0 |
External IdP (Auth0) | This server only verifies tokens; Auth0 (or any OIDC/JWKS provider) remains the authorization server. Per-IdP-user APS providers cached in memory. |
aps-mcp-server-remote-proxy |
Separate OAuth proxy service | Relies on an OAuth proxy in front of APS authentication (simple-oauth-proxy) to generate "MCP tokens", and uses /internal/exchange endpoint to exchange these for "APS tokens". |
simple-oauth-proxy |
(is the proxy) | The standalone, provider-agnostic OAuth proxy service consumed by aps-mcp-server-remote-proxy, built with Python + FastMCP. |
shared |
(library) | The five APS auth provider classes, the two MCP tools, and small helpers reused by every example above. |
Setup common to every example
- Register an APS application at https://aps.autodesk.com/myapps (a
Traditional Web App if you'll use any
3LOexample; a Server-to-Server / API-key style app is enough for2LO-only use). ForSSA, additionally create a Secure Service Account and register its public key — see the SSA guide. npm installat the repo root — this is an npm workspaces project, so one install resolvessharedand all four TypeScript servers.- Run any TypeScript example with
npm startfrom inside its folder (ornpm run start -w <package-name>from the root), after copying its.env.exampleto.envand filling in the values for your chosenAPS_AUTH_MODE. simple-oauth-proxyis a separate Python/FastMCP service — see its own README for setup; it's only needed if you're tryingaps-mcp-server-remote-proxy.
A note on scope
These are teaching examples, optimized to be read end-to-end in one sitting. Several corners intentionally cut for brevity are called out in the relevant README (in-memory-only state with no horizontal-scaling story, a simplified CIMD fetch without full SSRF hardening in the OAuth proxy example, etc.). Don't copy the security-relevant bits verbatim into production without reading those notes.
Recommended Servers
playwright-mcp
A Model Context Protocol server that enables LLMs to interact with web pages through structured accessibility snapshots without requiring vision models or screenshots.
Audiense Insights MCP Server
Enables interaction with Audiense Insights accounts via the Model Context Protocol, facilitating the extraction and analysis of marketing insights and audience data including demographics, behavior, and influencer engagement.
Magic Component Platform (MCP)
An AI-powered tool that generates modern UI components from natural language descriptions, integrating with popular IDEs to streamline UI development workflow.
VeyraX MCP
Single MCP tool to connect all your favorite tools: Gmail, Calendar and 40 more.
graphlit-mcp-server
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. Ingest anything from Slack to Gmail to podcast feeds, in addition to web crawling, into a Graphlit project - and then retrieve relevant contents from the MCP client.
Kagi MCP Server
An MCP server that integrates Kagi search capabilities with Claude AI, enabling Claude to perform real-time web searches when answering questions that require up-to-date information.
Neon Database
MCP server for interacting with Neon Management API and databases
Exa Search
A Model Context Protocol (MCP) server lets AI assistants like Claude use the Exa AI Search API for web searches. This setup allows AI models to get real-time web information in a safe and controlled way.
Qdrant Server
This repository is an example of how to create a MCP server for Qdrant, a vector search engine.
E2B
Using MCP to run code via e2b.