Authentication
Integrator appendix. Remote Legate is an OAuth resource server. Your org IdP (or Stratum as token broker) issues short-lived JWTs. Legate verifies them.
Buyer-facing authority story: Access model. This page is the interface only, not IdP broker internals or policy source.
Model
| Actor | Role at the interface |
|---|---|
| MCP client | Presents Authorization: Bearer on remote tool calls |
| IdP / Stratum BFF | Issues audience-bound tokens after login / consent |
| Legate | Verifies JWT (JWKS), enforces audience/resource, maps scopes to packs |
Bearer JWT
POST /mcp
Authorization: Bearer <token>
- Token
aud(andresourcewhen present) matches the Legate resource URI - Tokens minted for other APIs are rejected
- Do not log raw Bearer tokens
Discovery
Unauthenticated remote calls receive 401 with a WWW-Authenticate challenge that includes a resource_metadata URL (RFC 9728).
GET /.well-known/oauth-protected-resource
Scopes and packs
| Pack | Typical use |
|---|---|
legate.read | Observe / query scoped shared state |
legate.write | simulate / prepare / submit_signed sequence |
No scope or pack claims → empty packs (deny by default) on remote HTTP.
Write consent
Prepare/submit tools require an explicit write consent claim. A read-scoped token cannot escalate by calling a write tool name.
Stdio note
Local stdio on a trusted operator machine may use a different local identity path. Not a substitute for remote JWT auth in multi-user environments.