Developer · Local MCP server

MCP Opa Authz

Authorization answers from real policy code: evaluate Rego locally, or ask an AuthZEN 1.0 PDP.

Visit MCP Opa Authz's website

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.kanywst/mcp-opa-authz
Version
0.6.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
OCI image (Docker)
Published
2026-10-03
Updated
2026-10-03
Publisher
kanywst (GitHub)
Website
github.com/kanywst/mcp-opa-authz#readme
Repository
github.com/kanywst/mcp-opa-authz
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
OCI image (Docker)ghcr.io/kanywst/mcp-opa-authz:0.6.0—stdioAUTHZEN_PDP_URL, AUTHZEN_PDP_TOKEN (secret), AUTHZEN_PDP_TIMEOUT, MCP_OPA_EVAL_TIMEOUT, MCP_OPA_ALLOW_NETWORK_BUILTINS

How to connect MCP Opa Authz

MCP Opa Authz runs locally from a container image in an OCI registry such as Docker Hub or GitHub Container Registry: ghcr.io/kanywst/mcp-opa-authz:0.6.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Docker or another OCI container runtime; started with docker run — the usual command is docker run -i --rm -e AUTHZEN_PDP_URL -e AUTHZEN_PDP_TOKEN -e AUTHZEN_PDP_TIMEOUT -e MCP_OPA_EVAL_TIMEOUT -e MCP_OPA_ALLOW_NETWORK_BUILTINS ghcr.io/kanywst/mcp-opa-authz:0.6.0. It reads these environment variables: AUTHZEN_PDP_URL, AUTHZEN_PDP_TOKEN (secret), AUTHZEN_PDP_TIMEOUT, MCP_OPA_EVAL_TIMEOUT and MCP_OPA_ALLOW_NETWORK_BUILTINS; set them in the client's configuration for this server.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "mcp-opa-authz": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "-e",
        "AUTHZEN_PDP_URL",
        "-e",
        "AUTHZEN_PDP_TOKEN",
        "-e",
        "AUTHZEN_PDP_TIMEOUT",
        "-e",
        "MCP_OPA_EVAL_TIMEOUT",
        "-e",
        "MCP_OPA_ALLOW_NETWORK_BUILTINS",
        "ghcr.io/kanywst/mcp-opa-authz:0.6.0"
      ],
      "env": {
        "AUTHZEN_PDP_URL": "<value>",
        "AUTHZEN_PDP_TOKEN": "<secret>",
        "AUTHZEN_PDP_TIMEOUT": "<value>",
        "MCP_OPA_EVAL_TIMEOUT": "<value>",
        "MCP_OPA_ALLOW_NETWORK_BUILTINS": "<value>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
MCP Observability ServerMCP server for querying logs from observability platforms with unified search and tracing.Local · stdioPyPI: mcp-observability-server
MCP ObservatoryMCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.Local · stdionpm: @kryptosai/mcp-observatory
MCP Obsidian CliSave chat notes from Claude Desktop to your vault — MCP on Obsidian CLI. Keep what matters.Local · stdionpm: mcp-obsidian-cli
MCP OciOracle Cloud discovery + Terraform generation for AI agents — read-only, secret-safe.Local · stdionpm: @dockndevai/mcp-oci
MCP Openapi RunnerTurn any OpenAPI 3.x spec into callable MCP tools for Claude. No custom integration code needed.Local · stdionpm: mcp-openapi-runner
MCP OpenClaw Extensions138-tool MCP server for AI agent firms: security, A2A, Hebbian memory, fleet mgmt.Local · stdioPyPI: mcp-openclaw-extensions
MCP OpenpayMCP server for Openpay — BBVA-owned Mexican gateway (cards, SPEI, OXXO, subscriptions, payouts)Local · stdionpm: @codespar/mcp-openpay
MCP OpenshiftSafe-by-default MCP for OpenShift / Kubernetes: projects, pods, logs, deployments, routes.Local · stdionpm: @dockndevai/mcp-openshift