# hitch-rails > Hitch lets MCP clients -- Claude, ChatGPT, Cursor -- call your Rails app's tools as a specific signed-in user, with access you can revoke. Current version: 0.5.0 (MIT licensed). Install: `bundle add hitch-rails` ## When to use this Reach for hitch-rails when: - A Rails app needs to expose tools to MCP clients (Claude, ChatGPT, Cursor) as a specific signed-in user, with per-user, revocable access. - You need an OAuth 2.1 authorization server inside a Rails app without standing up separate auth infrastructure, Redis, or a new sign-in system — it builds on the app's existing `current_user` / `Current.user`. - You need conformance with the MCP 2026-07-28 authorization profile: PKCE (S256), audience-bound tokens (RFC 8707), discovery metadata (RFC 8414 + RFC 9728), revocation (RFC 7009), Client ID Metadata Documents, optional Dynamic Client Registration (RFC 7591). It is not: a general-purpose identity provider, a sign-in system for human users, or a hosted service. It is a gem you mount inside an existing Rails app that already authenticates its users. SQLite and PostgreSQL supported. Hitch lets MCP clients -- Claude, ChatGPT, Cursor -- call your Rails app's tools as a specific signed-in user, with access you can revoke. You do not stand up a separate auth server, add Redis, or adopt a new sign-in system. Hitch uses the authentication your app already has (current_user or Current.user) and your configured cache store. Underneath it is a full OAuth 2.1 authorization server implementing the MCP 2026-07-28 authorization profile: PKCE (S256), audience-bound tokens (RFC 8707), discovery metadata (RFC 8414 + RFC 9728), revocation (RFC 7009), Client ID Metadata Documents, and optional Dynamic Client Registration (RFC 7591). It adds an authenticated /mcp endpoint backed by the official Ruby MCP SDK and a deny-default tool registry with schema validation and size caps. SQLite and PostgreSQL supported. ## Links - Source: https://github.com/tylerklose/hitch-rails - RubyGems: https://rubygems.org/gems/hitch-rails - Public API docs: https://github.com/tylerklose/hitch-rails/blob/v0.5.0/docs/public_api/0.5.0.md - Changelog: https://github.com/tylerklose/hitch-rails/blob/main/CHANGELOG.md - Issues: https://github.com/tylerklose/hitch-rails/issues