Skip to main content
Go Reference CI Release License: MIT A Go auth library where OAuth 2.1 MCP authorization, agent identities, and revocable delegation chains ship in a single import. Drop it into a chi or net/http server in a few lines. Store sessions in Postgres, MySQL, SQLite, or memory.

Install

Requires Go 1.25+.

Quick Start

Run it:

What it covers

Documentation

  • Getting Started - Installation, quick start, storage backends
  • Concepts - OAuth 2.1, MCP authorization, AS/RS roles
  • Guides - Step-by-step task guides
  • Reference - Config shape, errors, metrics, spans, audit events
  • Security - Threat model, release verification
  • Migrations - Upgrade guides between versions
  • Changelog - Full release history

MCP Resource Server

For MCP servers that only need token validation (no auth server), install the zero-dependency SDK:
See Resource Server (mcpresource) for the full walkthrough.
Last modified on October 7, 2026