Authenticate Scalar MCP servers
Control who can connect#
Every installation is private by default. Choose Public for anyone with the URL, Team for team members using a personal access token or OAuth, or Access group for allowed emails or domains using OAuth, email, or SSO.
Authenticate upstream requests#
Configure upstream authentication per installation:
- Global — Store one credential on the installation. Scalar uses it for every call and agents never see it.
- Passthrough — Let each caller supply a credential. Scalar forwards it for the request without storing it.
Next steps#
- Create an MCP server — Select the operations an installation exposes.
- Get started with Scalar Agent — Connect an agent runtime.