Rocketlane's MCP server ships 24 tools to Claude, Cursor, and ChatGPT. Scalekit handles the OAuth 2.1 layer in front of it — live in days, with the existing auth system untouched and EU customers covered from day one.
Rocketlane is a delivery and customer-onboarding platform used by professional services teams to plan, run, and report on client projects. Its customers sit on both sides of the Atlantic — a meaningful share in the EU — which means every new access surface has to clear the same residency bar the core product already does.
When customer interviews made it clear that PS teams wanted to work from inside Claude and Cursor rather than tab-switching into Rocketlane, the product call was easy. Standing up compliant, production-grade auth for it — without touching the system already running the app — was the harder problem.
"Scalekit cut our MCP auth integration from weeks to 2 days, with near-zero code, seamless org-switching, and support that jumped on a call within few minutes whenever we needed it."
Rocketlane's production auth system already runs the web app and every existing integration. MCP meant a new, standards-compliant OAuth 2.1 surface on top of it — one that couldn't risk what was already live.
Core auth runs the entire product and every existing integration. MCP auth had to sit alongside it, with zero risk to live sessions or SSO.
Customer interest in MCP was already there. Every week spent building an OAuth 2.1 server from scratch was interest with nowhere to go.
A real share of customers are in Europe. MCP had to meet the same data residency bar as the rest of the product — not as a follow-up project.
Scalekit terminates the OAuth 2.1 handshake and routes the token to a region-scoped vault before it ever reaches Rocketlane's MCP server. Rocketlane's own auth system stays completely out of the path.
"Our customers wanted to work inside Claude and Cursor, not just inside Rocketlane. Scalekit let us meet them there — live in days, EU residency built in, nothing rebuilt in our own auth stack."
Bolting OAuth 2.1 onto an existing login system usually costs more than building it alongside. Keep the boundary clean from day one.
If your product already makes regional guarantees, your MCP layer needs the same ones — routed, not re-engineered per region.
The tools are the interesting part. Refresh, revocation, and per-tool scopes across five different MCP clients is where teams lose weeks.
The same auth layer, whichever MCP client your customers connect from — and wherever they're regulated to sit.
We use cookies, so things load fast, we learn what to fix, and you can always reach us on chat