MCP Gateway / Add OAuth to TypeScript functions
Add OAuth to TypeScript functions
Learn how to implement OAuth authentication in TypeScript functions for secure third-party integrations.
Integrating OAuth into Speakeasy Functions is a simple process: declare which environment variable should carry the token, and the platform handles the OAuth exchange and supplies the token to the function on every call.
Access requirements
Section titled “Access requirements”Configuring OAuth on the MCP server that exposes the function requires the mcp:write scope, and attaching a remote identity provider requires org:admin. The default Admin role includes both. Pushing the function itself requires project:write.
Accessing the token
Section titled “Accessing the token”const gram = new Gram({ envSchema: { GOOGLE_ACCESS_TOKEN: z.string().describe("Google OAuth2 access token"), }, authInput: { oauthVariable: "GOOGLE_ACCESS_TOKEN", },}).tool({ name: "search_files", description: "Search for PDF files in Google Drive. Takes a search query and returns matching files based on their filename.", async execute(ctx, input) { const token = ctx.env.GOOGLE_ACCESS_TOKEN; return fetch(`https://www.googleapis.com/drive/v3/files`, { headers: { Authorization: `Bearer ${token}` }, }); },});The authInput object specifies which environment variable should be populated with the OAuth token.
The platform then handles the OAuth exchange and automatically supplies the token to the function.
Note that this only works once OAuth is enabled for the MCP server, as described below.
Adding OAuth to the MCP server
Section titled “Adding OAuth to the MCP server”Configuring OAuth for an MCP server that contains Functions is the same as configuring OAuth for any other MCP server. Open the server from MCP Gateway > MCP and follow the steps in the OAuth guide to get started.
Caveats
Section titled “Caveats”Only one managed OAuth provider can be attached to an MCP server. However, other security schemes defined in an OpenAPI spec (API keys, bearer tokens, and so on) are still accepted alongside OAuth, so users can authenticate with whichever method they prefer. See Multiple security schemes for details.
An MCP server can contain any number of tools that do not require OAuth alongside tools that use a single OAuth provider.