Tuesday, September 29, 2026

#1177 - OIC MCP Gateway - Dedicated Gateway Authorization

Introduction 

The post covers the setup required to leverage dedicated gateway authorization.

There are 2 aspects -
  • IDCS Confidential app setup
  • Client configuration - in my case, Postman

IDCS Confidential app setup

Here we are required to do server and client configuration - 

Server Configuration

The Primary Audience value can be copied from OIC - 

Client Configuration


Essentially, we're giving access to tools:list and tools:call.

Copy client id and secret -

That's sorted! Let's now look at my MCP Gateway configuration. The OIC Project contains 1 integration, exposed as a tool - 

I expose the project as an MCP Server and then do the setup as per my previous blog post on this topic.

Let's check out my Gateway resources - 
The MCP Server entry points to the mcp server exposed by the project.

The Gateway is then activated, then I click Run - 

Here I'm in Postman - I create an MCP collection - I'm using the MCP Gateway URL.

I configure Authorization as follows - 

Scope is set to -

Note the scope is for tools:list and tools:call.

I get a token and use it to connect - 

I'm connected, so now I can click on Message -

I enter some order values and click Run - 

Summa Summarum

Dedicated Gateway Authorization is simple to implement and use. This will be the option of choice for many customers.












 







No comments:

Post a Comment