MCP Authentication
Sign in to Archestra once, and every tool call runs as you, in every app. Ask Claude Code to file a Jira ticket and comment on a GitHub pull request. With your own accounts installed, Jira and GitHub both show your name. You never pasted a token into Claude Code.
Every MCP server signs in its own way, and most clients cannot do it for a whole team. Archestra does it for them:
- One way in for each client. Coding agents authenticate through the browser. Scripts, apps, and your identity provider have their own methods. See MCP Gateway Authentication.
- The right account for each call. The person's own, a shared bot account, or their company identity, exchanged at call time. See MCP Server Credentials.
- Credentials stay in Archestra. It stores them, and refreshes OAuth tokens when the provider allows it. Clients never see them.
- Every call is traceable. The MCP Gateway logs show which account each call used.
Explore
MCP Gateway Authentication
Authenticate a client to an MCP Gateway with OAuth, a platform token, or your identity provider's JWT
Gateway Access for Apps
Let your own app or service call an MCP Gateway with an OAuth client
MCP Server Credentials
Set how Archestra signs in to each MCP server, and whose account each call uses