Authenticate Scalar MCP servers

Control who can connect#

Every installation is private by default. Choose Public for anyone with the URL, Team for team members using a personal access token or OAuth, or Access group for allowed emails or domains using OAuth, email, or SSO.

Authenticate upstream requests#

Configure upstream authentication per installation:

  • Global — Store one credential on the installation. Scalar uses it for every call and agents never see it.
  • Passthrough — Let each caller supply a credential. Scalar forwards it for the request without storing it.

Next steps#

Updated

Was this page helpful?