AI Briefing
KOSign in

Ramen enables per-person OAuth for Claude Code MCP tools

·2026.10.04 09:47

Key point

The open-source tool replaces shared API keys with individual sign-ins, logging every call under the user's name with one-hour token lifetimes.

Details

Ramen, an open-source and self-hosted solution, allows teams to connect Claude Code to shared MCP tools using per-person OAuth instead of a single shared API key. This approach ensures that every tool call is logged under the specific user's name, enhancing accountability and security.

How it works

  • Authentication: Users sign in via a browser flow within Claude Code, approving access once for a specific group and zone.
  • Token Management: Access tokens are short-lived, expiring after one hour.
  • Role-Based Access: Administrators can assign an "MCP user" role that restricts permissions to connection only.

Infrastructure and Compatibility

The backend consists of a git repository of Python tools that are canary-deployed to Rust + Python workers on GKE or EKS, both of which are verified for this release. While Claude Code supports the OAuth flow, Claude Desktop currently requires a group key because it lacks support for dynamic client registration needed for OAuth in this context.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.