Use this procedure to configure OAuth for the MCP in Drata.
Required Drata roles: Admin
Configure an OAuth configuration
Go to Settings.
Select MCP OAuth Configuration. You must be an administrator in Drata to access this page.
Enter a name for the OAuth configuration.
Enter a description of the configuration.
Set an expiration date for the configuration.
Select the scopes you want to configure.
After you configure the scopes, follow the setup instructions for your specific MCP client.
Drata provides a remote hosted MCP server at:
https://mcp.drata.com/mcp/ # Official UShttps://mcp-euc1.drata.com/mcp/ # EUhttps://mcp-apse2.drata.com/mcp/ # APAC
End users can access only the intersection of the OAuth scopes you configure and the permissions granted by their assigned roles. Users cannot access anything beyond what their roles inside the application allow while using the Drata MCP.
OAuth scopes
The following table describes each available OAuth scope and the roles that can use it.
OAuth Scope | Description | Allowed Roles |
read:risk | View Risks in Risk Registers | Admin, Risk Manager, Risk Register Owner, Workspace Administrator |
read:controls | View Controls list | Admin, Control Manager, DevOps Engineer, Risk Manager, Risk Register Owner, Information Security Lead, Workspace Administrator |
read:control | View Control details and requirements | Admin, Control Manager, DevOps Engineer, Information Security Lead, Workspace Administrator |
read:policy | View Policies | Admin, Policy Manager, Information Security Lead, Workspace Administrator |
read:workspace | View Workspaces | Admin |
read:risk-registers | View Risk Registers | Admin, Risk Manager |
read:assigned-policies | View User Assigned Policies | Admin, Control Manager, DevOps Engineer, Employee, Internal Auditor, Knowledge Base, People Ops, Policy Manager, Reviewer, Risk Manager, Information Security Lead, Trust Center Manager, Trust Center Reviewer, Workspace Administrator |
read:monitor-test | View Monitoring Tests | Admin, Control Manager, DevOps Engineer, Information Security Lead, Workspace Administrator |
