Configuration
Prerequisites
Before you begin, you will need:- A Google Cloud Account with access to create OAuth 2.0 Client IDs
- Your FastMCP server’s URL (can be localhost for development, e.g.,
http://localhost:8000)
Step 1: Create a Google OAuth 2.0 Client ID
Create an OAuth 2.0 Client ID in your Google Cloud Console to get the credentials needed for authentication:1
Navigate to OAuth Consent Screen
Go to the Google Cloud Console and select your project (or create a new one).First, configure the OAuth consent screen by navigating to APIs & Services → OAuth consent screen. Choose “External” for testing or “Internal” for G Suite organizations.
2
Create OAuth 2.0 Client ID
Navigate to APIs & Services → Credentials and click ”+ CREATE CREDENTIALS” → “OAuth client ID”.Configure your OAuth client:
- Application type: Web application
- Name: Choose a descriptive name (e.g., “FastMCP Server”)
- Authorized JavaScript origins: Add your server’s base URL (e.g.,
http://localhost:8000) - Authorized redirect URIs: Add your server URL +
/auth/callback(e.g.,http://localhost:8000/auth/callback)
3
Save Your Credentials
After creating the client, you’ll receive:
- Client ID: A string ending in
.apps.googleusercontent.com - Client Secret: A string starting with
GOCSPX-
Step 2: FastMCP Configuration
Create your FastMCP server using theGoogleProvider, which handles Google’s OAuth flow automatically:
server.py
Testing
Running the Server
Start your FastMCP server with HTTP transport to enable OAuth flows:Testing with a Client
Create a test client that authenticates with your Google-protected server:test_client.py
- Your browser will open to Google’s authorization page
- Sign in with your Google account and grant the requested permissions
- After authorization, you’ll be redirected back
- The client receives the token and can make authenticated requests
The client caches tokens locally, so you won’t need to re-authenticate for subsequent runs unless the token expires or you explicitly clear the cache.
Production Configuration
For production deployments with persistent token management across server restarts, configurejwt_signing_key and client_storage:
server.py
Parameters (
jwt_signing_key and client_storage) work together to ensure tokens and client registrations survive server restarts. Wrap your storage in FernetEncryptionWrapper to encrypt sensitive OAuth tokens at rest - without it, tokens are stored in plaintext. Store secrets in environment variables and use a persistent storage backend like Redis for distributed deployments.For complete details on these parameters, see the OAuth Proxy documentation.
