Skip to content

Add AWS STS authentication tutorial and cross-references#561

Closed
Copilot wants to merge 3 commits intomainfrom
copilot/sub-pr-550
Closed

Add AWS STS authentication tutorial and cross-references#561
Copilot wants to merge 3 commits intomainfrom
copilot/sub-pr-550

Conversation

Copy link

Copilot AI commented Feb 18, 2026

Description

Tutorial covering end-to-end setup of ToolHive as an authentication proxy for the AWS MCP Server on Kubernetes. Users register their OIDC provider with AWS IAM, create IAM roles with the aws-mcp permission model, configure MCPExternalAuthConfig with type: awsSts, and deploy an MCPRemoteProxy pointing to the AWS MCP Server endpoint.

Type of change

  • New documentation

Related issues/PRs

#510

Screenshots

N/A

Submitter checklist

Content and formatting

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

Navigation

  • New pages include a frontmatter section with title and description at a minimum
  • Sidebar navigation (sidebars.ts) updated for added, deleted, reordered, or renamed files
  • Redirects added to vercel.json for moved, renamed, or deleted pages (i.e., if the URL slug changed)

Reviewer checklist

Content

  • I have reviewed the content for technical accuracy
  • I have reviewed the content for spelling, grammar, and style

💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

jhrozek and others added 3 commits February 18, 2026 10:02
Tutorial covering end-to-end setup of ToolHive as an authentication
proxy for the AWS MCP Server on Kubernetes. Users register their
OIDC provider with AWS IAM, create IAM roles with the aws-mcp
permission model, configure MCPExternalAuthConfig with type: awsSts,
and deploy an MCPRemoteProxy pointing to the AWS MCP Server endpoint.

Also adds cross-references from existing token exchange and remote
proxy docs so readers discover the AWS-specific auth path:

- concepts/backend-auth: mention AWS STS in the federation section,
  add "Built-in AWS STS support" subsection
- guides-k8s/token-exchange-k8s: link in Related information
- guides-k8s/remote-mcp-proxy: tip admonition after token exchange
  section

Fixes: #510
- Fix OIDC issuer placeholder: rename <YOUR_OIDC_ISSUER_HOST> to
  <YOUR_OIDC_ISSUER>, clarify it excludes the https:// scheme and
  must include path components (avoids doubled-scheme copy-paste
  error and works for Okta/Keycloak issuers with paths)
- Clarify roleClaim vs claim: explain that roleClaim defaults to
  "groups" when omitted, that the claim field under roleMappings
  is a value to match (not a claim name), and show how to override
  the claim name for other IdPs
- Remove misleading region suggestion: the AWS MCP Server endpoint
  only exists in us-east-1
- Add Gateway API note and connect-clients cross-reference in Step 5
- Move role selection admonition from Step 2 to Step 3 where the
  priority field first appears
- Add AWS CLI to prerequisites
- Replace stale "7 of 9 tools" with "most tools"
- Mention jq dependency alongside oauth2c at point of use
- Simplify line highlighting to {4,7}
- Remove "Optionally" from IAM cleanup
@vercel
Copy link

vercel bot commented Feb 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
docs-website Ready Ready Preview, Comment Feb 18, 2026 10:04am

Request Review

Copilot AI changed the title [WIP] Add AWS STS authentication tutorial and cross-references Add AWS STS authentication tutorial and cross-references Feb 18, 2026
Copilot AI requested a review from jhrozek February 18, 2026 10:05
Base automatically changed from aws_sts to main February 18, 2026 10:07
@jhrozek jhrozek closed this Feb 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments