APS MCP Auth Examples
OfficialIntegrates with Autodesk Platform Services (APS), providing tools to list projects and folder contents via the Data Management API, with support for multiple OAuth authentication modes and per-user or app-wide access.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@APS MCP Auth Exampleslist projects in my APS account"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
APS MCP Auth Examples
Reference implementations of MCP servers that integrate with Autodesk Platform Services, covering every combination of:
How the server authenticates to APS
2LO- 2-legged OAuth, app-wide3LO- 3-legged OAuth, per-userPKCE- 3-legged OAuth for public clients, per-userSSA- Secure Service Account, non-human identity
How MCP clients authenticate to the server
not at all (STDIO)
via an external identity provider
via an OAuth proxy service
All HTTP-based examples target the 2026-07-28 MCP specification revision
via the split MCP TypeScript SDK v2
(@modelcontextprotocol/{server,express,node}), which requires MCP servers to
act as OAuth 2.1 resource servers backed by a dedicated authorization server,
and prefers Client ID Metadata Documents (CIMD) over Dynamic Client
Registration for identifying MCP clients.
Every example exposes the same MCP tools, implemented once in shared/ and
reused everywhere: list-projects (hubs + projects, via the Data Management
API) and list-contents (a project's top-level folders, or a specific folder's
contents).
The examples
Folder | MCP-client auth | What it demonstrates |
none (STDIO) | The simplest possible setup — a locally spawned process, no MCP-layer auth at all. | |
External IdP (Auth0) | This server only verifies tokens; Auth0 (or any OIDC/JWKS provider) remains the authorization server. Per-IdP-user APS providers cached in memory. | |
Separate OAuth proxy service | Relies on an OAuth proxy in front of APS authentication ( | |
(is the proxy) | The standalone, provider-agnostic OAuth proxy service consumed by | |
(library) | The four APS auth provider classes, the two MCP tools, and small helpers reused by every example above. |
Related MCP server: Devcon MCP Workshop 2026
Setup common to every example
Register an APS application at https://aps.autodesk.com/myapps (a Traditional Web App if you'll use any
3LOexample; a Server-to-Server / API-key style app is enough for2LO-only use). ForSSA, additionally create a Secure Service Account and register its public key — see the SSA guide.npm installat the repo root — this is an npm workspaces project, so one install resolvessharedand all four TypeScript servers.Run any TypeScript example with
npm startfrom inside its folder (ornpm run start -w <package-name>from the root), after copying its.env.exampleto.envand filling in the values for your chosenAPS_AUTH_MODE.simple-oauth-proxyis a separate Python/FastMCP service — see its own README for setup; it's only needed if you're tryingaps-mcp-server-remote-proxy.
A note on scope
These are teaching examples, optimized to be read end-to-end in one sitting. Several corners intentionally cut for brevity are called out in the relevant README (in-memory-only state with no horizontal-scaling story, a simplified CIMD fetch without full SSRF hardening in the OAuth proxy example, etc.). Don't copy the security-relevant bits verbatim into production without reading those notes.
Two more that apply to the shared tools rather than to any one example:
No pagination. The Data Management API returns hubs, projects and folder contents one page at a time;
list-projectsandlist-contentsread only the first page, so a large account silently sees a truncated list. A real implementation follows thelinks.nextcursor until it's absent.Unbounded fan-out.
list-projectsissues onegetHubProjectscall per hub concurrently. Fine for the handful of hubs a typical account has; with many hubs it will hit APS rate limits, so cap the concurrency.
And three that apply to the auth providers in shared/:
Token caching is deliberately naive. Each provider holds one access token and re-requests it shortly before expiry. A real provider would key the cache by scope and share one in-flight request between concurrent callers.
Any refresh failure ends the session.
ThreeLeggedAuthProvidertreats every failed refresh as "sign in again". In production you'd distinguish a dead grant (HTTP 400invalid_grant— refresh token expired or revoked) from a transient one, so an APS outage doesn't discard a perfectly good session.State is in-memory and per-instance.
aps-mcp-server-remote-auth0keeps its per-user auth providers and pending sign-ins inlru-cacheinstances rather than plainMaps, so a long-running process doesn't grow without bound — but scaling out still means moving them to a shared store.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
No tool schema history has been recorded yet.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Hosted MCP server with managed OAuth for 15+ toolkits: Google Workspace, Fitbit, Oura, Kalshi, etc.
A MCP server built for developers enabling Git based project management with project and personal…
MCP server for Codat — companies, connections, invoices, bills and financial statements.
Related MCP Servers
- FlicenseAqualityCmaintenanceAn MCP server that exposes Autodesk Platform Services (APS) as tools for AI assistants to interact with the APS Data Management API. It enables users to authenticate and manage hubs, projects, and folders through a standardized interface.272-
- FlicenseNot gradedqualityDmaintenanceMCP server integrating Autodesk Platform Services, exposing tools for LLM clients like VS Code Copilot, with OAuth authentication and agentic workflow support.-
- FlicenseNot gradedqualityCmaintenanceExample MCP server for Autodesk Platform Services that demonstrates proper OAuth authorization with Auth0 as the first layer and APS 3-legged OAuth as the second layer. Enables querying APS projects and issues through natural language after authenticating via Auth0 and APS.-
- AlicenseNot gradedqualityDmaintenanceA complete MCP server implementation demonstrating all protocol features (tools, resources, prompts, sampling, and elicitation) with OAuth authentication, serving as a learning resource and starting template for building MCP servers.MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/autodesk-platform-services/aps-mcp-auth-examples'
If you have feedback or need assistance with the MCP directory API, please join our Discord server