Gatana logoGatana Docs

Connecting to Gatana

How to authorize an MCP client with Gatana Gateway

There are three methods of authorizing an MCP client with the gateway:

  • OAuth 2.1: Use Gatana's OAuth 2.1 service to authorize
  • Personal Access Token: A static token, managed from Gatana App
  • Federated OIDC An access token from your organzation's federated identity provider

OAuth 2.1

To configure a client to use OAuth 2.1 you most often do this by specifying nothing at all. The MCP Client will connect to Gatana and discover authorization is required, and redirect you to sign-in using your standard web-browser automatically.

Example configuration:

{
  "Gatana": {
    "type": "http",
    "url": "https://YOUR_ORG_ID.gatana.ai/mcp"
  }
}

More Secure

Traditionally OAuth 2.1 has been the more secure method due to how MCP Client often handle static headers versus OAuth credentials. Additionally, the token is only valid for a limited time and sensitive information is commonly stored in the operating system's credential store.

The first time an app that is not one of Gatana's own signs in, the browser shows an approval screen: the app's name, what access it gets, and Approve and Deny buttons. Approving is remembered for that app on your account, so the screen is not shown again on later sign-ins or on other devices.

Once the client has signed in, it appears under Clients & API Keys in the left sidebar. From there you can rename the connection, attach profiles to it, see when it was last used, jump to its audit log, and disconnect it to revoke its access.

Personal Access Token

This is a more simple method of authorizing. It is a static token added in the HTTP Authorize header. You can create and manage your PAT:s under Clients & API Keys in the left sidebar of the Gatana App. The Connect button next to each token shows ready-made configuration for common clients (Claude Code, VS Code, Cursor, and others) with the token already filled in.

Example configuration:

{
  "Gatana": {
    "type": "http",
    "url": "https://YOUR_ORG_ID.gatana.ai/mcp",
    "headers": {
      "authorization": "Bearer THE_PERSONAL_ACCESS_TOKEN"
    }
  }
}

Federated OIDC

Gatana will accept access token that are issued by your organization's configured federated OIDC identity provider. Read more here: OIDC Access Token Trust.

Apps that connect this way are listed as federated clients under Clients & API Keys, where you can rename them and attach profiles.

On this page