Agent & MCP identity

The authorization server for your MCP tools

Obelisk signs your agents and MCP servers in the same verifiable way it signs people in. Your MCP server delegates every auth decision to Obelisk over standard OAuth 2.1 and verifies the tokens it mints — no login UI, no credential store, and no confused-deputy replay.

A standards-compliant MCP authorization server

Obelisk implements the MCP authorization profile end to end, so any compliant MCP client configures itself from discovery — you point at the live plane and delegate, you don't build an OAuth engine.

CapabilityWhat it gives your MCP server
OAuth 2.1 + PKCE (S256)The MCP auth baseline — public clients, no shared secret to store.
Resource indicators (RFC 8707)Access tokens are audience-bound to your server, so a token minted for someone else can't be replayed against you.
Issuer in the response (RFC 9207)Every authorization response carries iss — authorization-server mix-up defense.
Client ID Metadata DocumentsAn https client_id resolves to a metadata document, so clients you've never seen authenticate without pre-registration.
Protected-resource metadata (RFC 9728)Discovery at /.well-known/oauth-protected-resource points clients at the right authorization server from your server's 401.

Rehearse the trust flight

Select the capabilities an agent would ask for. This planning preview makes the policy consequence visible; it does not call a model or tool.

Policy postureLOW · read-only
Receipt shapeNo tool selected
RollbackNot applicable

Connect your MCP server

Your MCP server is the resource server: it advertises where to authorize, challenges an unauthenticated call, and verifies the audience-bound token Obelisk returns. Serve protected-resource metadata from your own origin so a compliant client discovers the Gate:

{
  "resource": "https://your-mcp.example.com",
  "authorization_servers": ["https://obeliskgate.com"],
  "bearer_methods_supported": ["header"]
}

Challenge an unauthenticated tool call with a 401 whose WWW-Authenticate names that document, then verify every incoming bearer token offline against the Gate's keys — checking that aud is your server (the RFC 8707 binding) and iss is https://obeliskgate.com. Use OIDC (iss, sub) as the caller's stable identity — the sub resolves to a human or an agent principal, so a production-mutation tool can gate on how the caller proved themselves. The full flow and a copy-paste verifier live in the developer & OIDC guide.

Never paste credentials into a config. Obelisk mints short-lived, audience-bound tokens and records the authorized use — never a secret you have to hold.

The four-step contract

  1. Discover. Read /agents.json and /.well-known/llms.txt, then the full contract as the API manifest or a standard OpenAPI 3.1 document.
  2. Authorize. The MCP client runs OAuth 2.1 + PKCE against the Gate, requesting your server as the resource — the access token comes back audience-bound to you, and the client may identify by a metadata document with no pre-registration.
  3. Constrain. Grants bind actor, capability, target, expiry, and caveats; a privileged tool requires an explicit capability grant, never ambient authority.
  4. Verify. Mutations emit attempt and outcome receipts, including rollback/recovery state.

What failure looks like

ConditionObelisk response
Unknown toolRejected before dispatch; never treated as a harmless extension.
Missing or expired grantDenied with a closed reason; omission never widens access.
Untrusted MCP outputRemains untrusted input until policy classifies the next action.
Mutation failsOutcome receipt records failure, rollback, and recovery truth separately.

Obelisk is also an MCP tool server — call it right now

Everything above is Obelisk as the authorization server your MCP server delegates to. Obelisk is also a public MCP tool server: any MCP-capable assistant can call 8 read-only trust tools over JSON-RPC at POST /mcp, no account required — the same endpoint, the machine-callable side.

ToolWhat it answers
scan_trustRun Obelisk's public trust scan on an https URL — TLS and security-header posture, scored as an Obelisk Rating. Read-only, SSRF-guarded.
verify_tokenVerify that a JSON Web Token was minted by this Obelisk Gate (ES256, correct issuer) and report its type, subject, assurance, and principal. Never returns secrets.
get_org_ratingRead the public Obelisk Rating (0-100 score, trust band, and trend) for a registered organization by its slug.
verify_agent_run_proofVerify the structural integrity, agent binding, delegation continuity, and commitments of an Obelisk action-scoped run proof. Does not reveal or infer raw task data.
get_agent_proofRead an Obelisk agent's public proof vector by opaque proof id. Returns independent claims with freshness and scope; never a scalar trust score or a claim of non-humanness.
transparency_headRead the current signed transparency head of Obelisk's tamper-evident receipt ledger — pin it and compare later to prove history only extends. Same data as /.well-known/obelisk-transparency.json.
gate_statusRead the Gate's public liveness facts: issuer, served code revision, OIDC availability, and supported protocols. No posture internals.
explain_ratingExplain what an Obelisk Rating number means: its trust band, how the public scan scores, and what typically moves a score. Deterministic by default; pass narrate:true for an additional one-line model-written narrative (cached, public-scope, never required). Pure function of the number — no data is read.

Discovery: the plain catalogue at /mcp/tools, and agents.json advertises the endpoint to crawling agents. Point any MCP client at https://obeliskgate.com/mcp and ask it whether something is trustworthy.

What we don't claim

Straight about maturity: Obelisk runs as a hosted, single-region plane on self-operated infrastructure with auto-rollback on deploy — expect a few seconds of downtime on a release, not a 99.99% multi-region SLA, and formal compliance certifications are tracked on the roadmap and deliberately not implied elsewhere rather than in hand today. None of this touches the protocol correctness of the flow above; these are operational-maturity caveats, stated plainly so you can decide with open eyes.

Choose the next surface

Inspect the agent contract, browse the tool catalogue, put Obelisk in front of your own app with the SDK & OIDC guide, turn a team into a measurable boundary in Organizations, browse every endpoint in the API reference, or talk to us.