Opa Authz MCP Server
by kanywstio.github.kanywst/mcp-opa-authzv0.6.1
Authorization answers from real policy code: evaluate Rego locally, or ask an AuthZEN 1.0 PDP.
context tax
queued
security
queued
cold start
queued
freshness
Active3d ago
Install Opa Authz MCP server
Install in Claude Code
claude mcp add opa-authz -e AUTHZEN_PDP_TOKEN='<authzen-pdp-token>' -- docker run -i --rm -e AUTHZEN_PDP_TOKEN ghcr.io/kanywst/mcp-opa-authz:0.6.1Install in Cursor
{
"mcpServers": {
"opa-authz": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"AUTHZEN_PDP_TOKEN",
"ghcr.io/kanywst/mcp-opa-authz:0.6.1"
],
"env": {
"AUTHZEN_PDP_TOKEN": "<authzen-pdp-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"opa-authz": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"AUTHZEN_PDP_TOKEN",
"ghcr.io/kanywst/mcp-opa-authz:0.6.1"
],
"env": {
"AUTHZEN_PDP_TOKEN": "<authzen-pdp-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"opa-authz": {
"type": "stdio",
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"AUTHZEN_PDP_TOKEN",
"ghcr.io/kanywst/mcp-opa-authz:0.6.1"
],
"env": {
"AUTHZEN_PDP_TOKEN": "<authzen-pdp-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"opa-authz": {
"command": "docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"AUTHZEN_PDP_TOKEN",
"ghcr.io/kanywst/mcp-opa-authz:0.6.1"
],
"env": {
"AUTHZEN_PDP_TOKEN": "<authzen-pdp-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| AUTHZEN_PDP_URL | — | — | Default AuthZEN Access Evaluation endpoint, e.g. https://pdp.example.com/access/v1/evaluation. Only evaluate_policy works without it. |
| AUTHZEN_PDP_TOKEN | — | yes | Authorization header value for the PDP. A value with no scheme is sent as "Bearer <token>". |
| AUTHZEN_PDP_TIMEOUT | — | — | Per-request timeout for PDP calls, as a Go duration. Default 10s. |
| MCP_OPA_EVAL_TIMEOUT | — | — | Wall-clock limit on a single Rego evaluation, as a Go duration. Default 5s. |
| MCP_OPA_ALLOW_NETWORK_BUILTINS | — | — | Re-enable http.send, net.lookup_ip_addr and opa.runtime inside evaluated policies. Off by default: policy source evaluated here comes from a model and runs inside the server process. |
Freshness
Active — last maintenance signal 3d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-10-07 · 3d ago · GitHub
Latest release
2026-10-07 · 3d ago · GitHub · v0.6.1
Package published
no data · npm/PyPI
Registry entry updated
2026-10-07 · 3d ago · official registry · v0.6.1
FAQ
›How do I install the Opa Authz MCP server in Claude Code?
Run: claude mcp add opa-authz -e AUTHZEN_PDP_TOKEN='<authzen-pdp-token>' -- docker run -i --rm -e AUTHZEN_PDP_TOKEN ghcr.io/kanywst/mcp-opa-authz:0.6.1. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Opa Authz require an API key?
Yes. It expects AUTHZEN_PDP_TOKEN, of which 1 is a secret.
›Can I use Opa Authz as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Opa Authz in the official MCP registry?
Yes, as io.github.kanywst/mcp-opa-authz.