# Any roadmap to support authorization headers soon?

**URL:** <https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134>\
**Category:** MCP Server\
**Created:** [June 3, 2025, 2:37pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134 "2025-06-03T14:37:55Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 3, 2025, 2:37pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/1 "2025-06-03T14:37:55Z")

</div>

Hi! Are there any plans to support custom authorization headers in Apollo MCP Server soon? Would be great to know if it’s on the near roadmap.  
is there any indirect way to support custom auth headers for now?

---

<div class="post-metadata">

**Author:** ![rob-fusco](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/rob-fusco/32/6154_2.png) [@rob-fusco](https://community.apollographql.com/u/rob-fusco)\
**Post date:** [June 3, 2025, 6:55pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/2 "2025-06-03T18:55:30Z")

</div>

While I had no success (so far) including an Authorization header via MCP Inspector, I was able to successfully make authenticated calls to our internal supergraph via the MCP server by setting the header on the docker container startup. Not the perfect solution for our use case, but if you are using an API key for a service account, it may suffice.

```auto
	docker run --rm -p 5000:5000 \
	  -v "$(PWD)/my-schema.graphql" \
	  ghcr.io/apollographql/apollo-mcp-server:v0.3.0 \
	  --introspection \
	  --schema /data/supergraph.graphql \
	  --log debug \
	  --header "Authorization: Bearer "$(TOKEN) \
	  --endpoint https://my-supergraph/graphql

```

---

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 3, 2025, 7:16pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/3 "2025-06-03T19:16:07Z")

</div>

Thank you! But my application is multi-tenant and token-based, so I need to send different tokens depending on the tenant

---

<div class="post-metadata">

**Author:** ![kevin\_chu](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/kevin_chu/32/5518_2.png) [@kevin\_chu](https://community.apollographql.com/u/kevin_chu)\
**Post date:** [June 3, 2025, 8:52pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/4 "2025-06-03T20:52:35Z")

</div>

Hey @Maximiliano_Ozernick I am the product manager for our MCP Server. MCP Auth is top of mind and we are looking into it now. I would love to hear about your project, let me know if you are open to sharing it and we can set something up. Same for you @rob-fusco!

---

<div class="post-metadata">

**Author:** ![rob-fusco](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/rob-fusco/32/6154_2.png) [@rob-fusco](https://community.apollographql.com/u/rob-fusco)\
**Post date:** [June 3, 2025, 9:50pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/5 "2025-06-03T21:50:34Z")

</div>

In short, our hope was to include an bearer token in the `Authorization` header when making the request to the MCP server and having it be passed along to the Apollo supergraph. Via debugging, we can see the header being received by the MCP server, but when making the request to supergraph the header is not present.

We are running the MCP server in SSE mode (in Streamable mode, we do not observe headers in the MCP server logs). We are using Python and the LangChain MCP adapter to connect to the Apollo MCP server and this successfully sends the header to the MCP server as we can observe it in the debug logs of rmcp (sse\_servers.rs line 70).

We are literally working through this today as we speak, so details are evolving. Apologies for any gaps.

---

<div class="post-metadata">

**Author:** ![jmbp1999](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/jmbp1999/32/1855_2.png) [@jmbp1999](https://community.apollographql.com/u/jmbp1999)\
**Post date:** [June 4, 2025, 5:46am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/6 "2025-06-04T05:46:01Z")

</div>

Hi , @rob-fusco when running the SSE server

 ![image](https://us1.discourse-cdn.com/flex019/uploads/apollographql/original/2X/3/33fbfb15d259080b85633f6cc3265798d2115f78.png)  
like this, is there any paths to the SSE endpoint. i mean /sse. because using mcp SSEserverparams , i cant connect to the endpoint directly

---

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 4, 2025, 7:31am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/7 "2025-06-04T07:31:22Z")

</div>

Hi @kevin_chu,

Thank you for the reply.

We have an Apollo GraphQL endpoint that can accept either a custom token we generate or a JWT, both sent via the Authorization header.

The token includes the necessary data to authenticate and identify the user.

As long as we can pass the headers through to the endpoint, we should be all set.

Do you have an estimate for when this functionality could be available?

Thank you!

---

<div class="post-metadata">

**Author:** ![matthew.hawkins](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/matthew.hawkins/32/5537_2.png) [@matthew.hawkins](https://community.apollographql.com/u/matthew.hawkins)\
**Post date:** [June 5, 2025, 4:13pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/8 "2025-06-05T16:13:53Z")

</div>

The [MCP specification](https://modelcontextprotocol.io/specification/draft/basic/authorization#2-7-2-token-handling) doesn’t allow for this kind of token pass-through. Tokens must be validated by the MCP server, and tokens sent by the MCP client can only come from the authorization server associated with the MCP server.

Proper auth handling based on the MCP spec is on our roadmap and is currently in the design phase.

---

<div class="post-metadata">

**Author:** ![rob-fusco](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/rob-fusco/32/6154_2.png) [@rob-fusco](https://community.apollographql.com/u/rob-fusco)\
**Post date:** [June 5, 2025, 5:43pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/9 "2025-06-05T17:43:42Z")

</div>

Thanks for the link, still getting up to speed on all the MCP specs. Lots of reading lately.

We use okta as an OAuth authorization server, so we are willing to follow all the specs as written. I think our main requirement is to have the server backing the supergraph be responsible for authorization of data access. User A can access user A’s data, but not user B’s data of the same resource. So as long as we can have a token that identifies the request to supergraph as attributable as the end user (and not some mcp server super powered service account) we would be good. Essentially we expect our LLMs to be acting on behalf of some end user who has access to a subset of data available via our supergraph.

Therefore we are super interested in dates and priority of auth handling based on MCP spec. I suspect you don’t have a set date if you are still in design, but any crumbs would be appreciated so we can do our planning.

---

<div class="post-metadata">

**Author:** ![mtinnes](https://avatars.discourse-cdn.com/v4/letter/m/e36b37/32.png) [@mtinnes](https://community.apollographql.com/u/mtinnes)\
**Post date:** [June 9, 2025, 12:10am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/10 "2025-06-09T00:10:24Z")

</div>

We utilize MCP on the server side and have been using environment variables for injecting auth tokens into the MCP server scope. It would be great if the Apollo MCP server could support something similar, essentially look for something like AUTH\_BEARER\_TOKEN in the environment, then forward this as an authorization header to the GraphQL endpoints.

---

<div class="post-metadata">

**Author:** ![matthew.hawkins](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/matthew.hawkins/32/5537_2.png) [@matthew.hawkins](https://community.apollographql.com/u/matthew.hawkins)\
**Post date:** [June 9, 2025, 3:59pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/11 "2025-06-09T15:59:32Z")

</div>

The MCP server has a `--header` option that allows you to specify static header values to be sent the GraphQL request. You should be able to use an environment variable to set that option when starting the server.

---

<div class="post-metadata">

**Author:** ![JMGaia](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/jmgaia/32/6183_2.png) [@JMGaia](https://community.apollographql.com/u/JMGaia)\
**Post date:** [June 10, 2025, 11:00pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/12 "2025-06-10T23:00:05Z")

</div>

@kevin_chu passing the Authorization request header from MCP server to the GraphQL server is a feature that I would plus one. Our use case matches what was described by @rob-fusco

An alternative would be if Rhai scripting support was added to MCP server and the script could pass the header. This is also how Apollo Router allowed custom implementations before they were available directly in the Router implementation.

> **[Rhai Scripts to customize routers](https://www.apollographql.com/docs/graphos/routing/customization/rhai)**
>
> Customize your Apollo Router Core or GraphOS Router functionality with Rhai scripts. Manipulate strings, process headers and more for enhanced performance.

---

<div class="post-metadata">

**Author:** ![JMGaia](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/jmgaia/32/6183_2.png) [@JMGaia](https://community.apollographql.com/u/JMGaia)\
**Post date:** [June 11, 2025, 2:35pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/13 "2025-06-11T14:35:44Z")

</div>

@kevin_chu it look like the Apollo Rover project has support for the MCP server, but not Apollo Router. The high level use case is Apollo MCP → Apollo Router → NodeJS Apollo Server to support LLM tools which can query Federated GraphQL. The access control is provided by the Apollo Server which is currently forwarded from Apollo Router. Apollo MCP would just be another step in the chain.

Maybe this would also work as part of Apollo Router and most of the other features could be inherited from the Router?

---

<div class="post-metadata">

**Author:** ![kevin\_chu](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/kevin_chu/32/5518_2.png) [@kevin\_chu](https://community.apollographql.com/u/kevin_chu)\
**Post date:** [June 14, 2025, 12:08am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/14 "2025-06-14T00:08:52Z")

</div>

@JMGaia

> it look like the Apollo Rover project has support for the MCP server, but not Apollo Router.

I am not sure what you mean by Rover has no support for Apollo Router, you can indeed start a locally running router via Rover. See [The Rover dev Command - Apollo GraphQL Docs](https://www.apollographql.com/docs/rover/commands/dev)

We’re working on Auth for MCP, will have more updates soon.

---

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 15, 2025, 11:54am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/15 "2025-06-15T11:54:21Z")

</div>

Thanks for you answers!

It’s still unclear how you plan to handle multi-tenant applications without allowing the endpoint to read and process the authentication header.

We have several GraphQL APIs that rely directly on the authentication header to identify the customer. Simply forwarding the token using the MCP authentication header would solve this for us.

If that’s not currently supported, how do you plan to support this feature in the near future?

Thanks.

---

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 16, 2025, 2:17pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/18 "2025-06-16T14:17:16Z")

</div>

BTW, wundergraph supports it

> **[MCP Gateway - WunderGraph](https://cosmo-docs.wundergraph.com/router/mcp#authentication)**
>
> Technical guide for using WunderGraph’s MCP Gateway to connect GraphQL APIs to AI models. Covers setup, configuration, and usage examples.

---

<div class="post-metadata">

**Author:** ![dom\_ham919](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/dom_ham919/32/6201_2.png) [@dom\_ham919](https://community.apollographql.com/u/dom_ham919)\
**Post date:** [June 16, 2025, 4:49pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/19 "2025-06-16T16:49:04Z")

</div>

@Maximiliano_Ozernick Does it not require us to use Cosmo?

---

<div class="post-metadata">

**Author:** ![Maximiliano\_Ozernick](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/maximiliano_ozernick/32/6153_2.png) [@Maximiliano\_Ozernick](https://community.apollographql.com/u/Maximiliano_Ozernick)\
**Post date:** [June 16, 2025, 5:11pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/20 "2025-06-16T17:11:20Z")

</div>

i did not tested it. but look like you have to migrate from apollo to cosmo

---

<div class="post-metadata">

**Author:** ![Cameron\_Mayfield](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/cameron_mayfield/32/6212_2.png) [@Cameron\_Mayfield](https://community.apollographql.com/u/Cameron_Mayfield)\
**Post date:** [June 18, 2025, 12:15am UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/21 "2025-06-18T00:15:23Z")

</div>

@kevin_chu This is our use case as well. Will token passthrough be supported?

---

<div class="post-metadata">

**Author:** ![JMGaia](https://sea1.discourse-cdn.com/flex019/user_avatar/community.apollographql.com/jmgaia/32/6183_2.png) [@JMGaia](https://community.apollographql.com/u/JMGaia)\
**Post date:** [June 18, 2025, 6:12pm UTC](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134/22 "2025-06-18T18:12:29Z")

</div>

@kevin_chu to rephrase

- Apollo Rover provides the Apollo MCP via the `--mcp` argument
- Apollo Router does not have anything similar (this was just an observation not a request)

Thank you for looking into Authentication support.

[Next page](https://community.apollographql.com/t/any-roadmap-to-support-authorization-headers-soon/9134.md?page=2)
