Calling External APIs from MCP Tools
When an MCP tool needs to call an authenticated downstream API, such as a third-party service like Google or Salesforce, or an internal API registered as a separate Descope Resource, your MCP server needs a credential scoped to that service.
The access token the MCP client sent your server is minted for your server, so it can't be forwarded downstream.
Your MCP server gets that credential the same way any service does: it uses the inbound token to fetch a Connection token from the Connection token endpoints, or exchanges it at the Descope STS for a token for another Resource.
Downstream Credential Access covers that pattern in full. This page covers what's specific to MCP servers.
How It Fits an MCP Server
Your MCP server plays two roles. Toward MCP clients such as Claude, Cursor, or your users' agents, it's a Resource that validates their access tokens.
Toward the Descope STS, it's a client of its own, with a client ID and secret it uses for token exchange. That server client is separate from the MCP clients that connect to it, and it lets policies and audit logs distinguish your server's exchanges from the MCP client that started the tool call.
See Register a Client for Your Server, for how the two roles fit together.
The MCP server plays two roles in one request. As a Resource, it validates the inbound token from the MCP client. As a Client, it authenticates to Descope STS using its own client credentials to exchange that token for a downstream credential.
Policy is evaluated against the full context at exchange time: the original user, the MCP client that initiated the request, and the MCP server making the exchange. All three appear in the audit log.
The exchange happens inside your tool handlers. When a tool runs, the handler exchanges the inbound token for the credential that tool needs, calls the downstream API, and returns only the result to the MCP client.
Setup
Follow the setup steps on Downstream Credential Access:
- Register a client for your MCP server with the Client Credentials grant type
- Store its client ID and secret in your MCP server's environment
- Define each downstream target as a Resource or Connection, and map your MCP server's scopes to Connection scopes
- Create a policy for which users and clients can reach each target
Then make the token exchange or Connection fetch request from your tool handlers.
SDK Support
The Descope Python MCP SDK handles the Connection fetch for you when you use its Connection token retrieval helpers, so your tool handlers don't build the request themselves. For the other MCP SDKs, see MCP SDKs.