Kong / Kong/developer.konghq.com
Identity: Authenticate a third party MCP client
- Dominant language
- Ruby
- Stars
- 28
- Forks
- 121
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 313
Description
## Jobs to be done (optional)
When this Epic ships, it should be possible for a customer to be able to use Kong Identity as the basis for authentication of an MCP server and authenticate to that server using an independent MCP client like Claude Code.
The solution should:
Demonstrate full support for the necessary elements of the MCP Authentication specification, including DCR and PCKE with Auth Code flow.
Integrate with the [MCP OAuth plugin](https://developer.konghq.com/plugins/ai-mcp-oauth2/)
Include at least one end-to-end documented example of how to set up the MCP server, MCP Auth plugin, and Kong Identity.
See also our [index of motivating use cases](https://docs.google.com/presentation/d/1XaZ91ix9bqKg5UV27-B6x9WQ8cQD4SE8Vqsa3qJpc0Y/edit?slide=id.g3b59ddd8ca2_0_0#slide=id.g3b59ddd8ca2_0_0).
## Definition of done
- Create a how to that explains how to set up the MCP server, MCP Auth plugin, and Kong Identity
- Something more will need to be done to ensure people find this from MCP/AI type things
## Information
DRP: Andrew J.
Aha: https://konghq.aha.io/epics/KID-E-3
## Due date (optional)
Feb 2026
## Size
L
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the MCP Authentication specification and the linked MCP OAuth plugin documentation, then determine how Kong Identity fits into the MCP server setup. Produce a documented end-to-end example covering DCR, PKCE, and the authorization-code flow, and explain how readers can discover it from MCP or AI documentation.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100