Openfga MCP Server

Connect [OpenFGA](https://openfga.dev/) and [Auth0 FGA](https://auth0.com/fine-grained-authorization) to AI agents via the Model Context Protocol.

Local serverstdioPython

What is the Openfga MCP MCP server?

Openfga mcp mcp server connects Openfga MCP to AI assistants that speak the Model Context Protocol. Connect OpenFGA and Auth0 FGA to AI agents via the Model Context Protocol.

What Openfga MCP does

Connect OpenFGA and Auth0 FGA to AI agents via the Model Context Protocol.

Tools it exposes

Once connected, the assistant can call these 4 tools directly:

  • Stores — Create, list, get, delete stores
  • Models — Create models with DSL, list, get, verify
  • Permissions — Check, grant, revoke permissions; query users and objects
  • OpenFGA — The OpenFGA tool exposed by this server

Installing the openfga mcp mcp server

Setup follows the standard MCP pattern: clone or install the server, then register it in your client's configuration file and restart the client. The configuration snippets on this page cover Claude Desktop, Claude Code and Cursor.

Configuration

Before the server will start you need to supply 5 environment variables: OPENFGA_MCP_API_URL, OPENFGA_MCP_TRANSPORT_HOST, OPENFGA_MCP_API_TOKEN, OPENFGA_MCP_API_CLIENT_ID, OPENFGA_MCP_API_CLIENT_SECRET. Keep credentials in your client's env block or a secrets manager rather than committing them.

Where it fits

Developer-tool servers are usually the first ones people connect, because they turn "help me with this code" into an assistant that can actually read the repo and act on it. Openfga MCP sits in that group, and the shape of its toolset — Stores, Models, Permissions among others — tells you what it is really for. Worth comparing against the other developer tools servers in this directory before you commit to one, since several overlap in scope but differ sharply in setup cost and permissions.

Practical notes

  • This server runs locally, so it operates with whatever access your machine and its credentials already have. Scope that deliberately rather than by default.
  • It will not start until its required credentials are present, so set those before wondering why the tools never appear.
  • Maintained by evansims, written in Python.
  • MCP clients ask for confirmation before each tool call by default. Keep that on while you learn what the openfga mcp mcp server actually does with your data.
  • Every entry in this directory is reviewed by hand before it goes live, and details are checked against the project's own documentation.

Available tools

ToolWhat it does
StoresCreate, list, get, delete stores
ModelsCreate models with [DSL](https://openfga.dev/docs/configuration-language), list, get, verify
PermissionsCheck, grant, revoke permissions; query users and objects
OpenFGAThe OpenFGA tool exposed by this server.

How to install the Openfga MCP MCP server

{
  "mcpServers": {
    "OpenFGA": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "--pull=always",
        "evansims/openfga-mcp:latest"
      ]
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
OPENFGA_MCP_API_URLEndpoint or connection string the server talks to.Yes
OPENFGA_MCP_TRANSPORT_HOSTEndpoint or connection string the server talks to.Optional
OPENFGA_MCP_API_TOKENCredential the server authenticates with.Yes
OPENFGA_MCP_API_CLIENT_IDConfiguration value read at startup.Optional
OPENFGA_MCP_API_CLIENT_SECRETCredential the server authenticates with.Yes

Example prompts to try

  • Use Openfga MCP to Stores.
  • Use Openfga MCP to Models.
  • Use Openfga MCP to Permissions.

Frequently asked questions

It connects Openfga MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 4 tools (Stores, Models, Permissions, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Openfga MCP directly.