Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.277 Latest v2.1.284 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · mcp

Authorization changeddocs/draft/tools/inspector/authorization

Nearest release: v2.1.221, published 22 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Upstream edited this page at 2 Aug 2026 23:45 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.

Upstream edited
Recorded here
Lines+16added
Lines−16removed
From line 56 where the diff opens
First seen 26 Aug 2026 this site's first read of the page
Recorded edits2to this page, all time

The whole hunk

from line 56, old and new numbered
/
lines
from line 56
5656 
5757The web app listens for the OAuth callback on its own URL, while the CLI and TUI deliberately share a second one:
5858 
59| Surface | Default callback | Why |
60| ------- | -------------------------------------- | ---------------------------------------------------------------------------------- |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
59| Surface | Default callback | Why |
60| - | - | - |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
6262| **CLI** | `http://127.0.0.1:6276/oauth/callback` | A dedicated loopback listener, so it doesn't collide with a running web Inspector. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
6464 
6565**Register `http://127.0.0.1:6276/oauth/callback`** on any IdP that requires pre-registered redirect URIs before using the CLI or TUI. A predictable default is the point: you register once and reuse it.
6666 
from line 83
8383 
8484## Where credentials live
8585 
86| File | Contents |
87| --------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
86| File | Contents |
87| - | - |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
9191 
9292The path to `oauth.json` is resolved in order: `MCP_INSPECTOR_OAUTH_STATE_PATH`, then `<MCP_STORAGE_DIR>/oauth.json` (see [Environment variables](/docs/draft/tools/inspector/configuration#environment-variables)), then the default above. All three clients resolve it the same way. Command-line `--client-id` / `--client-secret` / `--client-metadata-url` override `client.json`.
9393 
from line 122
122122 
123123The common case: a human completed OAuth in the web Inspector on this machine, and now a script wants to use that token.
124124 
125| Flag | Behavior |
126| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
125| Flag | Behavior |
126| - | - |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
132132 
133133A typical remote-VM sequence:
134134 
Feedback