{"_id":"@0x-wim/mcp-oauth","_rev":"4-3acc075fa89febc380f4cc36f79fec73","name":"@0x-wim/mcp-oauth","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@0x-wim/mcp-oauth","version":"0.1.0","author":{"name":"Kenton Varda","email":"kenton@cloudflare.com"},"license":"MIT","_id":"@0x-wim/mcp-oauth@0.1.0","maintainers":[{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"}],"homepage":"https://github.com/wim-web/mcp-oauth#readme","bugs":{"url":"https://github.com/wim-web/mcp-oauth/issues"},"dist":{"shasum":"d54324bbd5d9cc65ad19f1edf6247fe3b8fa5df9","tarball":"https://registry.npmjs.org/@0x-wim/mcp-oauth/-/mcp-oauth-0.1.0.tgz","fileCount":9,"integrity":"sha512-4QJVBfh7WDA6rMIrKNmO2hZaC3slfE7gY4ocCevjjh7CF6LRP/hliqGzBQpKhesdvrp4i7WxgrIAVslaomAAjw==","signatures":[{"sig":"MEYCIQCAmzOv22756UYaRWM7r5PjRdwV7Cd1n3dwxM7b0hRr4wIhAK2T35l7exwQqWijR6ZFkGfMzmNTlFrfe2gal2SoJmP3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":149693},"main":"dist/oauth-provider.js","type":"module","types":"dist/oauth-provider.d.ts","exports":{".":{"types":"./dist/oauth-provider.d.ts","import":"./dist/oauth-provider.js"},"./next":{"types":"./dist/next.d.ts","import":"./dist/next.js"},"./oidc":{"types":"./dist/oidc/index.d.ts","import":"./dist/oidc/index.js"}},"gitHead":"d517fd74cffec37377ed4293d29498647b137637","scripts":{"test":"vitest run","build":"tsdown","check":"npm run typecheck && npm run test","prettier":"prettier -w .","typecheck":"tsc","test:watch":"vitest","build:watch":"tsdown --watch","prepublishOnly":"npm run build"},"_npmUser":{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"},"repository":{"url":"git+https://github.com/wim-web/mcp-oauth.git","type":"git"},"_npmVersion":"11.9.0","description":"Platform-independent OAuth 2.1 authorization provider","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"^0.18.1","vitest":"^3.2.4","prettier":"^3.7.4","pkg-pr-new":"^0.0.62","typescript":"^5.9.3","@types/node":"^25.5.0","@changesets/cli":"^2.29.8","@changesets/changelog-github":"^0.5.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth_0.1.0_1774771096487_0.3745838648923705","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@0x-wim/mcp-oauth","version":"0.1.1","author":{"name":"Kenton Varda","email":"kenton@cloudflare.com"},"license":"MIT","_id":"@0x-wim/mcp-oauth@0.1.1","maintainers":[{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"}],"homepage":"https://github.com/wim-web/mcp-oauth#readme","bugs":{"url":"https://github.com/wim-web/mcp-oauth/issues"},"dist":{"shasum":"f484a510fb18f2820a454adaea7a61090bdfca76","tarball":"https://registry.npmjs.org/@0x-wim/mcp-oauth/-/mcp-oauth-0.1.1.tgz","fileCount":9,"integrity":"sha512-x5LYFnijKQZG/gGKiLO5I9lZfY2i2QcVKmbH0n/WnxF1v9G/h0CWXIPunZUbk3JjCzF8Ey73uDX9B6iI25WcaA==","signatures":[{"sig":"MEUCIQDwsLXB0EyBQ1S+hLlLapAaLQ8BSHsTJ+AsSAtfi2AMzwIgf6i3fFGpUuoFEfnAW9pFWpCNh2lQQWlT5QP27rHGUdU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0x-wim%2fmcp-oauth@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":149693},"main":"dist/oauth-provider.js","type":"module","types":"dist/oauth-provider.d.ts","exports":{".":{"types":"./dist/oauth-provider.d.ts","import":"./dist/oauth-provider.js"},"./next":{"types":"./dist/next.d.ts","import":"./dist/next.js"},"./oidc":{"types":"./dist/oidc/index.d.ts","import":"./dist/oidc/index.js"}},"gitHead":"aa2838bf43c36d78954cf47ca86b5e918e758ae5","scripts":{"test":"vitest run","build":"tsdown","check":"npm run typecheck && npm run test","prettier":"prettier -w .","typecheck":"tsc","test:watch":"vitest","build:watch":"tsdown --watch","prepublishOnly":"npm run build"},"_npmUser":{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"},"repository":{"url":"git+https://github.com/wim-web/mcp-oauth.git","type":"git"},"_npmVersion":"11.9.0","description":"Platform-independent OAuth 2.1 authorization provider","directories":{},"sideEffects":false,"_nodeVersion":"24.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"^0.18.1","vitest":"^3.2.4","prettier":"^3.7.4","pkg-pr-new":"^0.0.62","typescript":"^5.9.3","@types/node":"^25.5.0","@changesets/cli":"^2.29.8","@changesets/changelog-github":"^0.5.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth_0.1.1_1774771598549_0.7904608796163135","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@0x-wim/mcp-oauth","version":"0.2.0","author":{"name":"Kenton Varda","email":"kenton@cloudflare.com"},"license":"MIT","_id":"@0x-wim/mcp-oauth@0.2.0","maintainers":[{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"}],"homepage":"https://github.com/wim-web/mcp-oauth#readme","bugs":{"url":"https://github.com/wim-web/mcp-oauth/issues"},"dist":{"shasum":"b08e6938e1f54b8c4b86481889e53b01a093de19","tarball":"https://registry.npmjs.org/@0x-wim/mcp-oauth/-/mcp-oauth-0.2.0.tgz","fileCount":9,"integrity":"sha512-+GkmQKSPfXHJ4tSpAaDxZuMB4OYvzL9TslIpWN6x7861Xb1QcAT7jO7t4unsUIo6RtuNTm3CxZQcMIrUk9P0Ag==","signatures":[{"sig":"MEQCID1t2TmL6ILWRpwBpaXZH4kPRZTWg2kEZqYaM5ZbuFBJAiBmvuWQWjm7Km5W4oOEoWFYOQwvlpVrEtXpSGwHX9iW8A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0x-wim%2fmcp-oauth@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":132490},"main":"dist/oauth-provider.js","type":"module","types":"dist/oauth-provider.d.ts","exports":{".":{"types":"./dist/oauth-provider.d.ts","import":"./dist/oauth-provider.js"},"./next":{"types":"./dist/next.d.ts","import":"./dist/next.js"},"./oidc":{"types":"./dist/oidc/index.d.ts","import":"./dist/oidc/index.js"}},"gitHead":"887a5feac66f0d6f00c026b7ee86c90042f43aae","scripts":{"dev":"concurrently -n build,playground -c blue,green \"npm run build:watch\" \"npm --prefix playground run dev -- --port 3456\"","test":"vitest run","build":"tsdown","check":"npm run typecheck && npm run test","prettier":"prettier -w .","typecheck":"tsc","test:watch":"vitest","build:watch":"tsdown --watch","prepublishOnly":"npm run build"},"_npmUser":{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"},"repository":{"url":"git+https://github.com/wim-web/mcp-oauth.git","type":"git"},"_npmVersion":"11.11.0","description":"Platform-independent OAuth 2.1 authorization provider","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsdown":"^0.18.1","vitest":"^3.2.4","prettier":"^3.7.4","pkg-pr-new":"^0.0.62","typescript":"^5.9.3","@types/node":"^25.5.0","concurrently":"^9.2.1","@changesets/cli":"^2.29.8","@changesets/changelog-github":"^0.5.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth_0.2.0_1775654146168_0.24174708314882554","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@0x-wim/mcp-oauth","version":"0.2.1","description":"Platform-independent OAuth 2.1 authorization provider","type":"module","sideEffects":false,"exports":{".":{"import":"./dist/oauth-provider.js","types":"./dist/oauth-provider.d.ts"},"./next":{"import":"./dist/next.js","types":"./dist/next.d.ts"},"./oidc":{"import":"./dist/oidc/index.js","types":"./dist/oidc/index.d.ts"}},"main":"dist/oauth-provider.js","types":"dist/oauth-provider.d.ts","publishConfig":{"access":"public"},"scripts":{"dev":"concurrently -n build,playground -c blue,green \"npm run build:watch\" \"npm --prefix playground run dev -- --port 3456\"","build":"tsdown","build:watch":"tsdown --watch","check":"npm run typecheck && npm run test","typecheck":"tsc","test":"vitest run","test:watch":"vitest","prettier":"prettier -w .","prepublishOnly":"npm run build"},"author":{"name":"Kenton Varda","email":"kenton@cloudflare.com"},"license":"MIT","devDependencies":{"@changesets/changelog-github":"^0.5.2","@changesets/cli":"^2.29.8","@types/node":"^25.5.0","concurrently":"^9.2.1","pkg-pr-new":"^0.0.62","prettier":"^3.7.4","tsdown":"^0.18.1","typescript":"^5.9.3","vitest":"^3.2.4"},"repository":{"type":"git","url":"git+https://github.com/wim-web/mcp-oauth.git"},"gitHead":"07934d454441ffd529a006fc0cfa00b67ee24074","_id":"@0x-wim/mcp-oauth@0.2.1","bugs":{"url":"https://github.com/wim-web/mcp-oauth/issues"},"homepage":"https://github.com/wim-web/mcp-oauth#readme","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-HOCEWMsuaUBiR1HaAznaIED6CnCEAVrMpM160sU/Gg1ZZEoU+d5cYwKpNwbDBTOu/0iHQ8KFlRJJygWqvdhM/Q==","shasum":"32ab598a1d0e115d290dc63ccd84c5cebfe2904f","tarball":"https://registry.npmjs.org/@0x-wim/mcp-oauth/-/mcp-oauth-0.2.1.tgz","fileCount":9,"unpackedSize":135677,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@0x-wim%2fmcp-oauth@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGHeiOx/4JGshqgBuGBvOh19cjr/l9uuaUI+X+7ByWOwAiBe0Fw/t18+Bo5gsAYvLykOhf81WSaUbqrIvhAifV1hpg=="}]},"_npmUser":{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"},"directories":{},"maintainers":[{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-oauth_0.2.1_1775658504108_0.5317941329035685"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-29T07:58:16.387Z","modified":"2026-04-08T14:28:24.516Z","0.1.0":"2026-03-29T07:58:16.632Z","0.1.1":"2026-03-29T08:06:38.726Z","0.2.0":"2026-04-08T13:15:46.315Z","0.2.1":"2026-04-08T14:28:24.253Z"},"bugs":{"url":"https://github.com/wim-web/mcp-oauth/issues"},"author":{"name":"Kenton Varda","email":"kenton@cloudflare.com"},"license":"MIT","homepage":"https://github.com/wim-web/mcp-oauth#readme","repository":{"type":"git","url":"git+https://github.com/wim-web/mcp-oauth.git"},"description":"Platform-independent OAuth 2.1 authorization provider","maintainers":[{"name":"0x-wim","email":"rootuser.main+npm@gmail.com"}],"readme":"# @0x-wim/mcp-oauth\n\nPlatform-independent OAuth 2.1 provider, forked from [`@cloudflare/workers-oauth-provider`](https://github.com/cloudflare/workers-oauth-provider) with Cloudflare dependencies removed. Runs on Next.js, Node.js, and any standard fetch environment.\n\n## Installation\n\n```bash\nnpm install @0x-wim/mcp-oauth\n```\n\n## Packages\n\n| Entry point              | Contents                                                      |\n| ------------------------ | ------------------------------------------------------------- |\n| `@0x-wim/mcp-oauth`      | Core `OAuthProvider`, `MemoryStore`, `StorageAdapter`         |\n| `@0x-wim/mcp-oauth/next` | Next.js App Router helpers (`createOAuthHandlers`, `getAuth`) |\n| `@0x-wim/mcp-oauth/oidc` | OIDC discovery and ID token verification                      |\n\n## Storage\n\nInstead of Cloudflare KV, supply a `StorageAdapter`. `MemoryStore` is provided for development:\n\n```ts\nimport { OAuthProvider, MemoryStore } from '@0x-wim/mcp-oauth';\n\nconst provider = new OAuthProvider({\n  storage: new MemoryStore(),\n  // ...\n});\n```\n\nFor production, implement the `StorageAdapter` interface (`get`, `put`, `delete`, `list`) backed by Redis, a database, etc.\n\n## Basic Usage\n\n```ts\nimport { OAuthProvider, MemoryStore } from '@0x-wim/mcp-oauth';\n\nconst provider = new OAuthProvider({\n  storage: new MemoryStore(),\n  apiRoute: ['/api/'],\n  apiHandler: {\n    async fetch(request, env, ctx) {\n      return new Response(`Hello, ${ctx.props.username}`);\n    },\n  },\n  defaultHandler: {\n    async fetch(request, env, ctx) {\n      const url = new URL(request.url);\n      if (url.pathname === '/authorize') {\n        const oauthReqInfo = await env.OAUTH_PROVIDER.parseAuthRequest(request);\n        // ... render consent UI ...\n        const { redirectTo } = await env.OAUTH_PROVIDER.completeAuthorization({\n          request: oauthReqInfo,\n          userId: '1234',\n          scope: oauthReqInfo.scope,\n          props: { username: 'Alice' },\n        });\n        return Response.redirect(redirectTo, 302);\n      }\n      return new Response('Not found', { status: 404 });\n    },\n  },\n  authorizeEndpoint: '/authorize',\n  tokenEndpoint: '/oauth/token',\n  clientRegistrationEndpoint: '/oauth/register',\n});\n```\n\n## Next.js App Router\n\n```ts\n// app/[...oauth]/route.ts\nimport { createOAuthHandlers } from '@0x-wim/mcp-oauth/next';\nexport const { GET, POST, OPTIONS, DELETE, PUT, PATCH } = createOAuthHandlers(provider);\n```\n\nThe Next adapter automatically reconstructs the public request URL from\n`Forwarded`, `X-Forwarded-*`, and `Host` headers before calling the provider, so\nstandalone/Docker deployments do not leak internal hostnames in OAuth metadata\nor audience checks.\n\nAuthenticate requests in route handlers:\n\n```ts\nimport { getAuth } from '@0x-wim/mcp-oauth/next';\n\nconst auth = await getAuth(provider, request);\nif (!auth.authenticated) return auth.error;\n// auth.token.grant.props — your user data\n```\n\n## OIDC Helpers\n\n```ts\nimport { discoverOIDC, verifyIdToken, fetchUserInfo } from '@0x-wim/mcp-oauth/oidc';\n\nconst config = await discoverOIDC('https://accounts.google.com');\nconst payload = await verifyIdToken(idToken, {\n  jwks: config.jwks_uri,\n  issuer: config.issuer,\n  audience: 'your-client-id',\n});\n```\n\n## Key Options\n\nSee the upstream [README](https://github.com/cloudflare/workers-oauth-provider) for full option documentation. Differences from upstream:\n\n- `storage: StorageAdapter` — **required** (replaces `OAUTH_KV` binding)\n- No Cloudflare-specific setup needed (no `wrangler.jsonc`, no compatibility flags)\n\n## Standards\n\nOAuth 2.1 · RFC 8414 · RFC 9728 · RFC 7591 · RFC 8693 · RFC 8707 · [MCP Authorization](https://modelcontextprotocol.io/specification/2025-11-25/basic/authorization)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}