Duaer

Integrations

Set up MCP credentials in Duaer

Store MCP connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.

Connect an MCP server with OAuth

Use this credential when Authentication is MCP OAuth2 in the Duaer Client or Duaer Client Tool node:

  1. If the MCP server supports dynamic client registration, keep Use Dynamic Client Registration on, put the MCP server address in Server URL, and click Connect my account. Duaer registers a client and discovers the authorization endpoints.
  2. If it does not, turn that off and fill in Authorization URL, Access Token URL, Client ID, Client Secret, and Scope from the server’s docs. Register the Duaer OAuth Redirect URL with the server.
  3. Leave Resource URL empty unless the server requires a specific protected resource URL.

For an MCP server that takes a fixed token, skip this credential and choose Bearer Auth or Header Auth in the node.

MCP OAuth2 API fields in Duaer

In Duaer, choose MCP OAuth2 API when you create a credential, then fill in these fields:

  • Use Dynamic Client Registration: Default: on.
  • Server URL (required): Shown when Use Dynamic Client Registration is on.
  • Authorization URL (required): Shown when Grant Type is Authorization Code or PKCE.
  • Access Token URL (required): Shown when Use Dynamic Client Registration is off.
  • Client ID (required): Shown when Use Dynamic Client Registration is off.
  • Client Secret (required, secret): Shown when Use Dynamic Client Registration is off.
  • Scope: Shown when Use Dynamic Client Registration is off.
  • Resource URL: Optional. The exact protected resource URL required by the MCP server. Leave empty to use the server's default, discovered automatically.

In the provider’s app settings, register the OAuth Redirect URL that the Duaer credential dialog shows (https://<your-duaer-host>/rest/oauth2-credential/callback). Then click Connect my account in Duaer and approve access.

Optional settings shared by every Duaer OAuth2 credential: Grant Type, Auth URI Query Parameters, Authentication, Send Additional Body Properties, Additional Body Properties, Ignore SSL Issues (Insecure), Token Expired Status Code, Encrypted Tokens (JWE), JWKS URI, Inline JWKS in Client Registration. They are described under OAuth2 API.

Duaer nodes that use it: Duaer Client.

Save the connection in Duaer

Open Credentials and create MCP. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys.

Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.

Questions

Do MCP secret values appear in Duaer node parameters?

No. In Duaer, MCP secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

What usually stops a MCP credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields MCP expects, then confirm you can create credentials in that project.

In this section