Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
better-auth avatar

Agent Auth Mcp

  • 84 installs
  • 56 repo stars
  • Updated July 9, 2026
  • better-auth/agent-auth

Agent Auth MCP is a skill for using Agent Auth's MCP tools to discover providers, connect agents, and execute capabilities through the MCP protocol.

About

Agent Auth MCP is a skill for using Agent Auth's MCP tools to authenticate agents and execute provider capabilities inside MCP-enabled environments like Cursor and Claude Code. It documents a numbered workflow across 17 tools: list/search/discover providers, list and describe capabilities, connect an agent, then execute capabilities or manage host and key lifecycle. A developer uses it to grant an agent scoped provider access via the MCP protocol.

  • Uses Agent Auth MCP tools to authenticate agents and execute capabilities
  • 17 MCP tools across discovery, capabilities, connect, and lifecycle
  • Configurable in Cursor and Claude Desktop via npx @auth/agent-cli mcp

Agent Auth Mcp by the numbers

  • 84 all-time installs (skills.sh)
  • Ranked #1,072 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

agent-auth-mcp capabilities & compatibility

Free; runs the auth-agent MCP server via npx, provider approval may be required.

Capabilities
agent auth · authentication · capability management
Use cases
security audit · orchestration
Pricing
Free
From the docs

What agent-auth-mcp says it does

Use the Agent Auth MCP tools to discover providers, connect agents, manage capabilities, and execute operations through the MCP protocol.
SKILL.md
The MCP server exposes 17 tools. Follow the numbered workflow below.
SKILL.md
Always start with `list_providers`.
SKILL.md
npx skills add https://github.com/better-auth/agent-auth --skill agent-auth-mcp

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs84
repo stars56
Last updatedJuly 9, 2026
Repositorybetter-auth/agent-auth

What it does

Authenticate an agent and execute Agent Auth provider capabilities through MCP tools in an MCP-enabled editor.

Who is it for?

Authenticating agents and executing scoped provider capabilities from an MCP-enabled editor.

Skip if: Environments without MCP support, where the Agent Auth CLI is used instead.

When should I use this skill?

You are in an MCP-enabled environment and need to authenticate an agent or run Agent Auth capabilities.

By the numbers

  • 17 MCP tools exposed
  • 4-step standard workflow

Files

SKILL.mdMarkdownGitHub ↗

Agent Auth MCP Tools

You have access to Agent Auth MCP tools for interacting with Agent Auth providers. Always prefer using these MCP tools for any agent authentication operations rather than making raw HTTP requests or writing custom code.

Starting the MCP Server

The MCP server is part of the CLI:

auth-agent mcp

Or with pre-configured providers:

auth-agent mcp --url https://api.example.com

Cursor / Claude Desktop configuration

{
  "mcpServers": {
    "auth-agent": {
      "command": "npx",
      "args": ["@auth/agent-cli", "mcp", "--url", "https://api.example.com"]
    }
  }
}

Available Tools

The MCP server exposes 17 tools. Follow the numbered workflow below.

Step 1: Discovery — Find a Provider

ToolParametersWhen to use
list_providers(none)Call this first. Lists all discovered/configured providers.
search_providersintent (required)Search the directory by name or intent (e.g. "deploy web apps", "vercel").
discover_providerurl (required)Look up a specific provider by URL. Only use if list/search didn't help.

Always start with `list_providers`. If empty, use search_providers or discover_provider.

Step 2: Capabilities — Understand What's Available

ToolParametersWhen to use
list_capabilitiesprovider (required), query, agent_id, limit, cursorList capabilities for a provider.
describe_capabilityprovider, name (required), agent_idGet full definition including input schema. Always call before executing.

Step 3: Connect — Authenticate an Agent

ToolParametersWhen to use
connect_agentprovider (required), capabilities, mode, name, reason, preferred_method, login_hint, binding_message, force_newConnect an agent to a provider. Returns agent_id.

Key parameters:

  • capabilities — Array of capability names to request.
  • mode"delegated" (acts for a user, default) or "autonomous" (independent).
  • preferred_method"device_authorization" (default, opens browser) or "ciba" (backchannel notification).
  • login_hint — User email for CIBA flow.
  • force_new — Create a new connection even if one exists.

Step 4: Use the Agent

ToolParametersWhen to use
execute_capabilityagent_id, capability (required), argumentsExecute a granted capability.
agent_statusagent_id (required)Check agent status, grants, and constraints.
sign_jwtagent_id (required), capabilities, audienceSign an agent JWT for manual use.
request_capabilityagent_id, capabilities (required), reason, preferred_method, login_hint, binding_messageRequest additional capabilities.
disconnect_agentagent_id (required)Revoke an agent.
reactivate_agentagent_id (required)Reactivate an expired agent.

Host Management

ToolParametersWhen to use
enroll_hostprovider, enrollment_token (required), nameEnroll a host with a one-time token.
rotate_agent_keyagent_id (required)Rotate an agent's keypair.
rotate_host_keyissuer (required)Rotate the host keypair for a provider.

Workflow Example

Here is the standard workflow for connecting to a provider and executing a capability:

1. list_providers
   → See what providers are already known

2. search_providers({ intent: "deploy web apps" })
   → Find a provider if none are known (or discover_provider with a URL)

3. list_capabilities({ provider: "https://api.example.com" })
   → See what the provider offers

4. describe_capability({ name: "deploy_app", provider: "https://api.example.com" })
   → Understand the input schema before executing

5. connect_agent({ provider: "https://api.example.com", capabilities: ["deploy_app"], name: "deploy-bot" })
   → Authenticate and get an agent_id
   → If approval is required, the user will be prompted

6. agent_status({ agent_id: "..." })
   → Confirm the agent is active and capabilities are granted

7. execute_capability({ agent_id: "...", capability: "deploy_app", arguments: { app: "my-app", env: "production" } })
   → Run the capability with the correct arguments

Important Rules

  • Never make raw HTTP requests to Agent Auth endpoints. Always use MCP tools.
  • Always call `list_providers` first. This tells you what's already configured.
  • Always call `describe_capability` before `execute_capability`. You need the input schema.
  • Always call `agent_status` after `connect_agent`. The agent may be pending approval.
  • Save the `agent_id` returned by connect_agent — every subsequent tool needs it.
  • Use constraints when connecting to limit agent permissions — pass them in the capabilities parameter as objects with name and constraints fields.
  • Handle approval flows. When connect_agent returns approval info (device code URL or CIBA), the user must approve before the agent becomes active. Poll agent_status to check.
  • Errors return structured objects like { error: "message", code: "error_code" } — check these and retry or adjust accordingly.

Capability Constraints

When connecting, you can restrict what an agent can do with its capabilities:

{
  "provider": "https://api.example.com",
  "capabilities": [
    "read_data",
    {
      "name": "transfer_money",
      "constraints": {
        "amount": { "max": 1000, "min": 1 },
        "currency": { "in": ["USD", "EUR"] }
      }
    }
  ]
}

Constraint types: eq (exact match), min/max (numeric bounds), in/not_in (allowed/blocked values).

When to Use CLI vs MCP

  • Use MCP tools when operating inside an MCP-enabled environment (Cursor, Claude Code, Claude Desktop) — the tools are already available and integrated.
  • Use the CLI when running from a terminal directly, scripting, or when MCP is not available.
  • Both expose the same operations and share the same storage (~/.agent-auth/).

Related skills

FAQ

Which tool should I call first?

Always start with list_providers; if empty, use search_providers or discover_provider.

How many tools does the MCP server expose?

The MCP server exposes 17 tools organized into a numbered discovery-to-execution workflow.

Securityappsecsecrets

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.