Skip to main content

MCP Setup

Updated today

Use this procedure to configure OAuth for the MCP in Drata.

Required Drata roles: Admin

Configure an OAuth configuration

  1. Go to Settings.

  2. Select MCP OAuth Configuration. You must be an administrator in Drata to access this page.

  3. Enter a name for the OAuth configuration.

  4. Enter a description of the configuration.

  5. Set an expiration date for the configuration.

  6. Select the scopes you want to configure.

  7. After you configure the scopes, follow the setup instructions for your specific MCP client.

Drata provides a remote hosted MCP server at:

  • https://mcp.drata.com/mcp/ # Official US

  • https://mcp-euc1.drata.com/mcp/ # EU

  • https://mcp-apse2.drata.com/mcp/ # APAC

End users can access only the intersection of the OAuth scopes you configure and the permissions granted by their assigned roles. Users cannot access anything beyond what their roles inside the application allow while using the Drata MCP.

OAuth scopes

The following table describes each available OAuth scope and the roles that can use it.

OAuth Scope

Description

Allowed Roles

read:risk

View Risks in Risk Registers

Admin, Risk Manager, Risk Register Owner, Workspace Administrator

read:controls

View Controls list

Admin, Control Manager, DevOps Engineer, Risk Manager, Risk Register Owner, Information Security Lead, Workspace Administrator

read:control

View Control details and requirements

Admin, Control Manager, DevOps Engineer, Information Security Lead, Workspace Administrator

read:policy

View Policies

Admin, Policy Manager, Information Security Lead, Workspace Administrator

read:workspace

View Workspaces

Admin

read:risk-registers

View Risk Registers

Admin, Risk Manager

read:assigned-policies

View User Assigned Policies

Admin, Control Manager, DevOps Engineer, Employee, Internal Auditor, Knowledge Base, People Ops, Policy Manager, Reviewer, Risk Manager, Information Security Lead, Trust Center Manager, Trust Center Reviewer, Workspace Administrator

read:monitor-test

View Monitoring Tests

Admin, Control Manager, DevOps Engineer, Information Security Lead, Workspace Administrator

MCP client setup instructions

  • For Claude, please refer to the instructions here.

  • For ChatGPT, please refer to the instructions here.

  • For Cursor, please refer to the instructions here.

  • For Microsoft Copilot, please refer to the instructions here.

Did this answer your question?