Authorization changeddocs/draft/tools/inspector/authorization
Nearest release: v2.1.221, published 22 hours after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 2 Aug 2026 23:45 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+16added
Lines−16removed
From line
56
where the diff opens
First seen
26 Aug 2026
this site's first read of the page
Recorded edits2to this page, all time
The whole hunk
from line 56, old and new numbered
/
from line 56
5656
5757The web app listens for the OAuth callback on its own URL, while the CLI and TUI deliberately share a second one:
5858
59| Surface | Default callback | Why |
60| ------- | -------------------------------------- | ---------------------------------------------------------------------------------- |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
59| Surface | Default callback | Why |
60| - | - | - |
61| **Web** | `http://localhost:6274/oauth/callback` | The main app server already has an HTTP listener. |
6262| **CLI** | `http://127.0.0.1:6276/oauth/callback` | A dedicated loopback listener, so it doesn't collide with a running web Inspector. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
63| **TUI** | `http://127.0.0.1:6276/oauth/callback` | The same listener as the CLI. |
6464
6565**Register `http://127.0.0.1:6276/oauth/callback`** on any IdP that requires pre-registered redirect URIs before using the CLI or TUI. A predictable default is the point: you register once and reuse it.
6666
from line 83
8383
8484## Where credentials live
8585
86| File | Contents |
87| --------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
86| File | Contents |
87| - | - |
88| `~/.mcp-inspector/storage/oauth.json` | Tokens and client information, keyed by canonicalized server URL. Written owner-only. |
89| `~/.mcp-inspector/storage/client.json` | Install-level client settings (client metadata URL, enterprise IdP). The same file the web client's **Client Settings** dialog writes. |
90| The server's `oauth` block in the [catalog file](/docs/draft/tools/inspector/configuration#catalog-file-format) | Per-server client id/secret, scopes, the enterprise-managed flag, and the [step-up](#mid-session-re-authorization) policy. |
9191
9292The path to `oauth.json` is resolved in order: `MCP_INSPECTOR_OAUTH_STATE_PATH`, then `<MCP_STORAGE_DIR>/oauth.json` (see [Environment variables](/docs/draft/tools/inspector/configuration#environment-variables)), then the default above. All three clients resolve it the same way. Command-line `--client-id` / `--client-secret` / `--client-metadata-url` override `client.json`.
9393
from line 122
122122
123123The common case: a human completed OAuth in the web Inspector on this machine, and now a script wants to use that token.
124124
125| Flag | Behavior |
126| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
125| Flag | Behavior |
126| - | - |
127| `--use-stored-auth` | Read the stored auth for `--server-url` and inject `Authorization: Bearer`. When a refresh token is stored, run the refresh grant first and inject the **fresh** token, persisting the rotation. Exits `3` (listing the stored server URLs) when nothing matches. |
128| `--wait-for-auth <sec>` | Poll the state file until a token for `--server-url` appears, then inject it. Times out at `<sec>` with exit `3`. Use after handing a login off to a human. |
129| `--list-stored-auth` | Print `{ oauthStatePath, storedServerUrls }` and exit without connecting. |
130| `--print-handoff` | Print a JSON block (`deepLink`, `portForwardCmd`, `oauthStatePath`, `apiToken`) for `--server-url` and exit; this is everything a remote script needs to drive the browser side. |
131| `--relogin` | Delete the stored OAuth for this server URL before connecting. HTTP/SSE only. |
132132
133133A typical remote-VM sequence:
134134
No line in this hunk matches that.