Skip to main content
This guide shows you how to secure your FastMCP server using Descope, a complete authentication and user management solution. This integration uses the Remote OAuth pattern, where Descope handles user login and your FastMCP server validates the tokens.

Configuration

Prerequisites

Before you begin, you will need:
  1. To sign up for a Free Forever Descope account
  2. Your FastMCP server’s URL (can be localhost for development, e.g., http://localhost:3000)

Step 1: Configure Descope

1

Create an MCP Server

  1. Go to the MCP Servers page of the Descope Console, and create a new MCP Server.
  2. Give the MCP server a name and description.
  3. Ensure that Dynamic Client Registration (DCR) is enabled. Then click Create.
  4. Once you’ve created the MCP Server, note your Well-Known URL.
DCR is required for FastMCP clients to automatically register with your authentication server.
2

Note Your Well-Known URL

Save your Well-Known URL from MCP Server Settings:

Step 2: Environment Setup

Create a .env file with your Descope configuration:

Step 3: FastMCP Configuration

Create your FastMCP server file and use the DescopeProvider to handle all the OAuth integration automatically:
server.py

Testing

To test your server, you can use the fastmcp CLI to run it locally. Assuming you’ve saved the above code to server.py (after replacing the environment variables with your actual values!), you can run the following command:
Now, you can use a FastMCP client to test that you can reach your server after authenticating:

Environment Variables

For production deployments, use environment variables instead of hardcoding credentials.

Provider Selection

Setting this environment variable allows the Descope provider to be used automatically without explicitly instantiating it in code.

FASTMCP_SERVER_AUTH
default:"Not set"
Set to fastmcp.server.auth.providers.descope.DescopeProvider to use Descope authentication.

Descope-Specific Configuration

These environment variables provide default values for the Descope provider, whether it’s instantiated manually or configured via FASTMCP_SERVER_AUTH.

FASTMCP_SERVER_AUTH_DESCOPEPROVIDER_CONFIG_URL
required
Your Well-Known URL from the Descope Console
FASTMCP_SERVER_AUTH_DESCOPEPROVIDER_BASE_URL
required
Public URL of your FastMCP server (e.g., https://your-server.com or http://localhost:8000 for development)
Example .env file:
With environment variables set, your server code simplifies to:
server.py