Skip to main content
When skills are exposed over HTTP (via skillsConfig.enabled), FrontMCP supports four authentication modes to protect skill endpoints.

Auth Modes

With inherit, a request to /skills, /llm.txt or /llm_full.txt must pass the same check as the MCP endpoint (a static key, a transparent token, a FrontMCP-issued token…); only a public-mode server lets everyone in. Skills with authorities are listed only for a caller whose verified claims satisfy them. In the other modes no claims are available, so those skills are never served over HTTP.

Configuration

Public Mode

Disable authentication on skill endpoints regardless of the parent server’s auth.

API Key Mode

Clients authenticate with either header format:
API key comparison uses timing-safe equality to prevent timing attacks. All configured keys are checked even after a match is found to maintain constant-time behavior.

JWT Bearer Mode

JWT tokens are validated against the issuer’s JWKS endpoint (auto-discovered from {issuer}/.well-known/jwks.json). A token must carry exp: one without it would never expire, so it is refused (401).

Validation Result

The validator returns a structured result:

Authorizing a Request

Use authorizeSkillHttpRequest() to apply skillsConfig.auth to a request. It covers every mode, including inherit (the default), for which it runs the server’s session:verify flow, and it returns the verified caller that skill authorities are evaluated against:

Header-Only Validator (api-key, bearer)

createSkillHttpAuthValidator() builds a validator that checks the request headers for an explicit auth: 'api-key' or auth: 'bearer'. It returns null only for auth: 'public'. It can’t run the server’s auth, so for inherit or an unset auth it refuses every request (500); use authorizeSkillHttpRequest() there.
Migrating from the null validator. createSkillHttpAuthValidator() used to return null for auth: 'inherit' and for an unset auth, so code that skipped validation on null served those requests with no auth at all. For those modes it now refuses every request (500). Switch that code to authorizeSkillHttpRequest(), shown above.

Tool Authorization Guard

When a skill session is active, the Tool Authorization Guard enforces which tools the skill is allowed to call. This prevents skill sessions from accessing tools outside their declared allowlist.

Policy Modes

Usage

Error Types

ToolNotAllowedError

Thrown when a tool is not in the skill’s allowlist (strict mode).

ToolApprovalRequiredError

Thrown when a tool requires approval but has not been approved yet.