> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP Authorization

> Install MCP Auth 4 with authenticated human consent, durable state, resource binding and issuer-side current authority.

## Installation

Published release: `@grantex/mcp-auth@4.1.0`. Its npm archive matches the
validated CI artifact. The earlier 4.0 consumer-flow evidence remains historical.

Deployment profile: `@grantex/mcp-auth@4.1.0`; confirm publication in
[release status](/release-status). Node.js 22.12+ and SDK 0.8.1+
are required; Node.js 24 LTS is recommended.

```bash theme={null}
npm install @grantex/mcp-auth@4.1.0 @grantex/sdk@0.8.2 pg
```

Read [release validation](/sdk-release-validation) and the
[breaking migration guide](/migration-enforcement) before upgrading.

## Authorization and deployment

Version 4 supplies OAuth 2.1 endpoints, PKCE S256, protected-resource
metadata, resource/audience binding, rendered consent, single-use codes,
refresh rotation and explicit token revocation configuration. The
[complete deployment guide](/mcp-auth) contains executable storage,
consent, middleware, lifecycle-hook and decision-grant examples.

1. Pin the canonical HTTPS issuer and protected resource.
2. Provision shared Postgres or Redis state and apply its migrations before scaling.
3. Supply `resolvePrincipal(request)` from a verified host session; live Grantex consent still requires a passkey. Approval and callback reject logout or a changed principal.
4. Connect resource middleware to the authorization server's revocation storage.
5. Supply `currentGrant: grantexCurrentGrantVerifier(grantex)` to check current issuer authority before protected execution. Mark sensitive tools decision-required and consume action-bound human decisions.
6. Test your client, proxy, storage restart/failure and principal handoff before production.

Memory storage remains evaluation-only. `revocations: 'none'` is a warned
opt-out, not revocation enforcement. Token revocation storage is not every
upstream grant-state check: the online verifier is also required. The host owns
verified principal login. Independent cross-vendor certification is not claimed.

See [MCP Auth Server](/features/mcp-auth-server) for the request flow and
operator responsibilities. The six immutable 2.0.2 limitations remain in
[the historical guide](/legacy/mcp-auth-server-2), not the version 4 deployment profile.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.