129 karma · joined March 9, 2017
If your tools are calling APIs on-behalf of users, it's better to use OAuth flows to enable users of the app to give explicit consent to the APIs/scopes they want the tools to access. That way, tools use scoped tokens to make calls instead of hard to manage, maintain API keys (or even client credentials).
Checkout the step-by-step quickstart [1] if you want to go through calling the Google Calendar API from an AI agent (Vercel AI SDK based in this case). There are also how-tos for other frameworks like LangGraph, GenKit, LlamaIndex, etc. Async authorization is also supported via CIBA (Client-Initiated Backchannel Authentication).
You can also secure remote MCP servers [1] with Auth0.
[0] https://auth0.com/ai/docs/call-others-apis-on-users-behalf [1] https://auth0.com/blog/secure-and-deploy-remote-mcp-servers-...
Disclosure: I work for Auth0.