OAuth MCP Servers¶
Note
OAuth MCP server support is available starting in Holmes 0.25.0.
Some MCP servers support OAuth-based authentication natively — you only need to set oauth.enabled: true and Holmes handles the rest. When Holmes connects to an OAuth-enabled MCP server, it automatically discovers the server's OAuth endpoints, opens a browser for login, and persists the token for future use.
Setup¶
To add an OAuth MCP server, set mode: streamable-http and oauth.enabled: true in the server's config:
In Kubernetes, the browser login and the stored token go through the Robusta platform, so Holmes must be connected to your Robusta account.
Set the CUSTOM_TOOLSET_LOCATION environment variable pointing to a YAML file with your MCP server configuration:
In that file, define your OAuth MCP servers:
When using the standalone Holmes Helm Chart, update your values.yaml:
mcp_servers:
my-server:
description: "Description of the MCP server"
config:
mode: streamable-http
url: https://example.com/mcp
oauth:
enabled: true
Apply the configuration:
Example: Atlassian¶
Running Holmes headlessly?
OAuth requires a browser consent screen. To connect the same Atlassian Rovo MCP server with a static credential instead, see Atlassian Rovo (MCP).
Step 1: Set up the Atlassian side
CLI users can skip this step.
- Go to https://admin.atlassian.com/ and select your organization
- Navigate to Rovo → Rovo MCP Server
-
Click Add domain and enter your Robusta platform URL, matching your region:
Region URL US (default) https://platform.robusta.dev/**EU https://platform.eu.robusta.dev/**AP https://platform.ap.robusta.dev/**
Step 2: Configure HolmesGPT
In Kubernetes, the browser login and the stored token go through the Robusta platform, so Holmes must be connected to your Robusta account.
When using the standalone Holmes Helm Chart, update your values.yaml:
mcp_servers:
atlassian:
config:
mode: streamable-http
url: https://mcp.atlassian.com/v1/mcp
oauth:
enabled: true
Apply the configuration:
How It Works¶
- Holmes detects that the MCP server has
oauth.enabled: true - Holmes discovers the server's OAuth configuration automatically via the MCP protocol
- The user is prompted to authenticate via their browser
- After login, Holmes exchanges the authorization code for an access token
- The token is persisted and refreshed automatically — users only need to authenticate once