# Auth0 MCP server

> Manage Auth0 applications, APIs, actions, logs, forms and client grants in your tenant using natural language.

- Listing: https://mcp.tc/i/auth0
- Connect: this is a local (stdio) server; install it on your machine (see Install). The listing link is a page, not an MCP endpoint.
- Type: local (stdio)
- Auth: OAuth sign-in
- Category: [Security & Compliance](https://mcp.tc/c/security)
- Vendor: Auth0 (Okta)
- Verified: yes, mcp.tc checked that this is the official server (https://mcp.tc/verify). It says who runs the server, not that it is safe.
- Homepage: <https://auth0.com/docs/get-started/auth0-mcp-server>
- Docs: <https://auth0.com/docs/get-started/mcp>
- Repository: <https://github.com/auth0/auth0-mcp-server>
- Package: npm `@auth0/auth0-mcp-server`

## About

Connects an AI assistant to the Auth0 Management API for your tenant. You can list, create and update applications, resource servers (APIs), actions, and forms, deploy actions, read tenant logs, create client grants for machine-to-machine access, and save application credentials to a project's env file.

It runs locally over stdio through npx and is currently in beta. Run the init command once to sign in through the Auth0 device authorization flow, and credentials are stored in the system keychain. Alternatively, set AUTH0\_TOKEN and AUTH0\_DOMAIN. A read-only mode and tool filtering limit what the assistant can change.

## What it can do

- List, create, get and update Auth0 applications
- Manage resource servers (APIs) and their settings
- Create, update and deploy Auth0 actions
- Search and read tenant logs
- Create and update forms
- Create client grants for machine-to-machine access
- Save application credentials to a project env file
- Restrict tools with read-only mode or tool filters

## Tools (21)

- `auth0_list_applications`: List applications in the tenant or search them by name.
- `auth0_get_application`: Get details about a specific application.
- `auth0_create_application`: Create a new application, OIDC compliant by default.
- `auth0_update_application`: Update an existing application.
- `auth0_save_credentials_to_file`: Write application credentials to a project's env file and add a .gitignore entry.
- `auth0_list_resource_servers`: List all resource servers (APIs) in the tenant.
- `auth0_get_resource_server`: Get details about a specific resource server.
- `auth0_create_resource_server`: Create a new resource server (API), RS256 signing by default.
- `auth0_update_resource_server`: Update an existing resource server.
- `auth0_list_actions`: List all actions in the tenant.
- `auth0_get_action`: Get details about a specific action.
- `auth0_create_action`: Create a new action.
- `auth0_update_action`: Update an existing action.
- `auth0_deploy_action`: Deploy an action.
- `auth0_list_logs`: List logs from the tenant.
- `auth0_get_log`: Get a specific log entry by ID.
- `auth0_list_forms`: List all forms in the tenant.
- `auth0_get_form`: Get details about a specific form.
- `auth0_create_form`: Create a new form.
- `auth0_update_form`: Update an existing form.
- `auth0_create_application_grant`: Create a client grant authorizing an application to call an API with set scopes.

## Example prompts

- "Create a new Auth0 application and give me the domain and client ID"
- "Check Auth0 logs for logins from IP address 192.108.92.3"
- "Create and deploy an Auth0 action that adds a custom claim to tokens"
- "List all APIs in my Auth0 tenant and their scopes"

## Install

### Claude Code

1. Run this in a terminal, in your project folder:

```bash
claude mcp add --transport stdio auth0 -- npx -y @auth0/auth0-mcp-server run
```

2. Start Claude Code and type `/mcp`. **auth0** should show as connected.

Add `--scope user` to make it available in every project.

### Claude Desktop

1. Open **Settings → Developer → Edit Config**. It opens `claude_desktop_config.json`. Add:

`claude_desktop_config.json`:

```json
{
  "mcpServers": {
    "auth0": {
      "command": "npx",
      "args": [
        "-y",
        "@auth0/auth0-mcp-server",
        "run"
      ]
    }
  }
}
```

2. Save the file and restart Claude Desktop.

Needs Node.js on your computer. The file lives in `~/Library/Application Support/Claude/` on macOS and `%APPDATA%\Claude\` on Windows.

### Cursor

[Add to Cursor](<https://cursor.com/install-mcp?name=auth0&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBhdXRoMC9hdXRoMC1tY3Atc2VydmVyIiwicnVuIl19>) (opens Cursor)

Or add it by hand to `~/.cursor/mcp.json` (all projects) or `.cursor/mcp.json` (this project):

`mcp.json`:

```json
{
  "mcpServers": {
    "auth0": {
      "command": "npx",
      "args": [
        "-y",
        "@auth0/auth0-mcp-server",
        "run"
      ]
    }
  }
}
```

Needs Node.js on your computer.

### VS Code

[Install in VS Code](<https://vscode.dev/redirect/mcp/install?name=auth0&config=%7B%22type%22%3A%22stdio%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40auth0%2Fauth0-mcp-server%22%2C%22run%22%5D%7D>) (opens VS Code)

Or from a terminal:

```bash
code --add-mcp '{"name":"auth0","type":"stdio","command":"npx","args":["-y","@auth0/auth0-mcp-server","run"]}'
```

Or commit it to the repo in `.vscode/mcp.json`:

`.vscode/mcp.json`:

```json
{
  "servers": {
    "auth0": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "@auth0/auth0-mcp-server",
        "run"
      ]
    }
  }
}
```

Needs Node.js on your computer.

### Devin Desktop

1. Add it to `~/.config/devin/mcp_config.json` (macOS and Linux) or `%APPDATA%\devin\mcp_config.json` (Windows):

`mcp_config.json`:

```json
{
  "mcpServers": {
    "auth0": {
      "command": "npx",
      "args": [
        "-y",
        "@auth0/auth0-mcp-server",
        "run"
      ]
    }
  }
}
```

2. Refresh the MCP server list in Cascade.

Devin Desktop is the new name for Windsurf.

### Codex

```bash
codex mcp add auth0 -- npx -y @auth0/auth0-mcp-server run
```

Or edit `~/.codex/config.toml` directly:

`config.toml`:

```toml
[mcp_servers.auth0]
command = "npx"
args = ["-y", "@auth0/auth0-mcp-server", "run"]
```

Needs Node.js on your computer.

### Gemini CLI

```bash
gemini mcp add auth0 npx -- -y @auth0/auth0-mcp-server run
```

This adds it to the current project. Add `-s user` to use it everywhere.

### Any client

Most clients that start local servers accept this shape:

```json
{
  "mcpServers": {
    "auth0": {
      "command": "npx",
      "args": [
        "-y",
        "@auth0/auth0-mcp-server",
        "run"
      ]
    }
  }
}
```

Zed puts servers under `context_servers` in its settings, with the same `command`, `args` and `env` fields.

Needs Node.js on your computer.

## Details

- Server version: 0.1.0-beta.10
- Last checked: 2026-10-03
- Listed: 2026-10-03
- Updated: 2026-10-03

---
Source: https://mcp.tc/i/auth0 (mcp.tc is an independent directory, not affiliated with this server's publisher). Corrections: https://mcp.tc/report
