Skip to content

Authentication

Integrator appendix. Remote Legate is an OAuth resource server. Your org IdP (or Stratum as token broker) issues short-lived JWTs. Legate verifies them.

Buyer-facing authority story: Access model. This page is the interface only, not IdP broker internals or policy source.

Model

ActorRole at the interface
MCP clientPresents Authorization: Bearer on remote tool calls
IdP / Stratum BFFIssues audience-bound tokens after login / consent
LegateVerifies JWT (JWKS), enforces audience/resource, maps scopes to packs

Bearer JWT

POST /mcp
Authorization: Bearer <token>
  • Token aud (and resource when present) matches the Legate resource URI
  • Tokens minted for other APIs are rejected
  • Do not log raw Bearer tokens

Discovery

Unauthenticated remote calls receive 401 with a WWW-Authenticate challenge that includes a resource_metadata URL (RFC 9728).

GET /.well-known/oauth-protected-resource

Scopes and packs

PackTypical use
legate.readObserve / query scoped shared state
legate.writesimulate / prepare / submit_signed sequence

No scope or pack claims → empty packs (deny by default) on remote HTTP.

Prepare/submit tools require an explicit write consent claim. A read-scoped token cannot escalate by calling a write tool name.

Stdio note

Local stdio on a trusted operator machine may use a different local identity path. Not a substitute for remote JWT auth in multi-user environments.

Was this page clear?