One MCP server for each way a server can want to be called. Register them in an aigw workspace with the auth shown, connect your MCP client to aigw, and call whoami on each: it says what credential the server actually received.
| Server URL | aigw auth | Settings |
|---|---|---|
https://lab.staging.aigw.app/none/mcp | None | |
https://lab.staging.aigw.app/bearer/mcp | Bearer token | token lab-bearer-token |
https://lab.staging.aigw.app/header/mcp | API key (named header) | header X-Lab-Key, value lab-header-key |
https://lab.staging.aigw.app/basic/mcp | Basic | user lab, password lab-password |
https://lab.staging.aigw.app/cc/mcp | OAuth2 (client credentials) | token URL https://lab.staging.aigw.app/cc/token, client lab-cc-client, secret lab-cc-secret |
https://lab.staging.aigw.app/person/mcp | Each person connects their own account | nothing else: aigw finds the sign-in and registers itself |
https://lab.staging.aigw.app/person-noreg/mcp | Each person connects their own account | client ID lab-preregistered (this sign-in does not allow registration); leave it empty to see the message |
https://lab.staging.aigw.app/down/mcp | None | always answers 503, for the unreachable path |
Per-person tokens last 5m0s, so you can watch aigw renew them.
to see what a person gets when a SaaS ends theirs.