Authenticate to MCP servers behind a tunnel changedconnectors/mcp-tunnels/oauth
Nearest release: v2.1.283, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 25 Sep 2026 18:00 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 25 Sep 2026 18:07 UTC.
Upstream edited
Recorded here
Lines+17added
Lines−10removed
From line
1
where the diff opens
First seen
31 Aug 2026
this site's first read of the page
Recorded edits3to this page, all time
## Understand how OAuth works through a tunnel ## Next steps ## How OAuth works through a tunnel
The whole hunk
from line 1, old and new numbered
/
from line 1
11# Authenticate to MCP servers behind a tunnel
22
3> Make OAuth sign-in work for MCP servers reached through an MCP tunnel when the authorization server or identity provider is inside your network. Covers the Tunnel OAuth configuration fields (issuer, authorization endpoint, token endpoint, registration endpoint, scopes) and the split-metadata alternative.
3> Make OAuth sign-in work for MCP servers reached through an MCP tunnel when the authorization server or identity provider is inside your network.
44
55<Note>
66 MCP tunnels are in research preview and are available to organizations on the Claude Enterprise plan by request. To request access, [submit the MCP tunnels interest form](https://claude.com/form/mcp-tunnels) or contact your Anthropic account team.
from line 8
88
99An MCP tunnel carries Claude's requests to an MCP server inside your network, but it does not authenticate to that server. Each tunneled server should still require OAuth, as the [MCP authorization specification](https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization) describes, so that a member signs in with their own account before Claude can call the server's tools. This page is for the administrator adding a tunneled server as a custom connector, and explains what to configure when the OAuth authorization server is itself only reachable inside your network.
1010
11If your authorization server is reachable from the public internet and its metadata advertises public URLs, you don't need anything on this page. Add the connector as described in [Set up an MCP tunnel](/docs/connectors/mcp-tunnels/setup#add-tunneled-servers-as-connectors) and members sign in as they would for any other connector.
11<Note>
12 If your authorization server is reachable from the public internet and its metadata advertises public URLs, you don't need anything on this page. Add the connector as described in [Set up an MCP tunnel](/docs/connectors/mcp-tunnels/setup#add-tunneled-servers-as-connectors), and members sign in as they would for any other connector.
13</Note>
1214
13## How OAuth works through a tunnel
15## Understand how OAuth works through a tunnel
1416
1517Two different parties make requests during an OAuth sign-in, and they reach your authorization server by different paths.
1618
17* **The member's browser** is redirected to the authorization endpoint to sign in and approve access. This request comes from the member's device, so the authorization endpoint must be a URL their browser can load, either on the public internet or on your corporate network. It can't be a `tunnel.anthropic.com` hostname, because tunnel hostnames accept connections only from Claude.
18* **Claude's servers** fetch the authorization server's metadata, register an OAuth client if the server supports dynamic registration, and exchange the authorization code for tokens at the token endpoint. These requests come from Anthropic's network, so the endpoints must be reachable from there, either publicly or through the tunnel.
19* **The member's browser** is redirected to the authorization endpoint to sign in and approve access. This request comes from the member's device, so the authorization endpoint must be a URL their browser can load, either on the public internet or on your corporate network. It can't be a `tunnel.anthropic.com` hostname, because tunnel hostnames accept connections only from Claude
20* **Claude's servers** fetch the authorization server's metadata, register an OAuth client if the server supports dynamic registration, and exchange the authorization code for tokens at the token endpoint. These requests come from Anthropic's network, so the endpoints must be reachable from there, either publicly or through the tunnel
1921
20By default Claude discovers all of these URLs from the metadata your MCP server and authorization server publish. When the authorization server sits inside your network, that metadata usually advertises internal hostnames. Claude then can't reach the token endpoint, or the member's browser is sent to an address it can't load, and sign-in fails.
22By default Claude discovers the authorization server's endpoint URLs from the metadata your MCP server and authorization server publish. When the authorization server sits inside your network, that metadata usually advertises internal hostnames. Claude then can't reach the token endpoint, or the member's browser is sent to an address it can't load, and sign-in fails.
2123
22You fix this by routing Claude's server-to-server calls through the tunnel and telling Claude explicitly which URL to use for each endpoint.
24You fix this sign-in failure by routing Claude's server-to-server calls through the tunnel and telling Claude explicitly which URL to use for each endpoint.
2325
2426## Route the authorization server through the tunnel
2527
from line 37
3537
3638## Set the Tunnel OAuth configuration
3739
38When you add the tunneled MCP server as a custom connector in **Organization settings > Connectors**, turn on **Tunnel OAuth configuration** in the connector dialog. The values you enter replace the ones Claude would otherwise read from the authorization server's metadata. Anthropic enables this option for each organization in the research preview on request, so if the toggle does not appear in the dialog, contact your Anthropic account team.
40When you add the tunneled MCP server as a custom connector in [**Organization settings > Connectors**](https://claude.ai/admin-settings/connectors), turn on **Tunnel OAuth configuration** in the connector dialog. The values you enter replace the ones Claude would otherwise read from the authorization server's metadata. Anthropic enables this option for each organization in the research preview on request, so if the toggle does not appear in the dialog, contact your Anthropic account team.
3941
4042| Field | What to enter | Example |
4143| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------- |
from line 49
4749
4850The paths after the hostname (`/authorize`, `/oauth/token`, and so on) are whatever your authorization server uses. Copy them from its metadata document, usually served at `/.well-known/oauth-authorization-server` or `/.well-known/openid-configuration`, and change only the scheme and host.
4951
50After you save the connector, connect it yourself from your own connector settings. Your browser should land on your sign-in page, and after you approve access the connector should show as connected. If either step fails, see [Troubleshooting](/docs/connectors/mcp-tunnels/troubleshooting#sign-in-redirects-to-a-tunnel-address-that-does-not-load).
52After you save the connector, connect it yourself from your own connector settings. Your browser should open your sign-in page, and after you approve access the connector should show as connected. If either step fails, see [Troubleshooting](/docs/connectors/mcp-tunnels/troubleshooting#sign-in-redirects-to-a-tunnel-address-that-does-not-load).
5153
5254## Publish split metadata instead
5355
from line 74
7274}
7375```
7476
75This approach also suits an authorization server that is publicly reachable but sits behind a source-IP allowlist that you don't want to open to Anthropic's egress ranges. The [platform troubleshooting guide](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/troubleshooting#oauth-fails-behind-a-source-ip-allowlist) walks through the same configuration.
77Publishing split metadata also suits an authorization server that is publicly reachable but sits behind a source-IP allowlist that you don't want to open to Anthropic's egress ranges. The [platform troubleshooting guide](https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/troubleshooting#oauth-fails-behind-a-source-ip-allowlist) walks through the same configuration.
7678
7779Use **Tunnel OAuth configuration** when the authorization server is a product whose metadata you can't edit, or when you prefer to keep tunnel-specific addresses out of the server's configuration. Use split metadata when you control the authorization server and want the configuration to apply to every client that discovers it through the tunnel.
80
81## Next steps
82
83* [Add tunneled servers as connectors](/docs/connectors/mcp-tunnels/setup#add-tunneled-servers-as-connectors): where you add the connector and turn on **Tunnel OAuth configuration**
84* [Troubleshoot OAuth sign-in](/docs/connectors/mcp-tunnels/troubleshooting#oauth-sign-in): fix sign-in redirects that don't load and token exchanges that fail
7885
No line in this hunk matches that.