{"_id":"@allardy/mcp-oauth-proxy","_rev":"8-07d1efd2957cf5e8568b04e878def0e4","name":"@allardy/mcp-oauth-proxy","dist-tags":{"latest":"0.3.3"},"versions":{"0.1.0":{"name":"@allardy/mcp-oauth-proxy","version":"0.1.0","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.1.0","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"1d3724df956eb5e4866a480dff230a896f85f4c5","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.1.0.tgz","fileCount":39,"integrity":"sha512-jhmygiTXXdaztnPpzYqCLUivsBZa+zxFGs4UMAMbDz8PIgYpJ/4rD1MZiJVY5V/TOhzo+gfxEdMfJ+ibY3pKzg==","signatures":[{"sig":"MEYCIQDWtXV1vKJaULsF9BtmGbXMBZ6g4+IXsW7p1j1PkI9SDQIhAJ/pn+EyLx1503l8YFgCMT1/xIQGSFIasE21Ol5BZ4AW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":44073},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/03f47a0dbe20745af12611ecd7b9d71e/allardy-mcp-oauth-proxy-0.1.0.tgz","_integrity":"sha512-jhmygiTXXdaztnPpzYqCLUivsBZa+zxFGs4UMAMbDz8PIgYpJ/4rD1MZiJVY5V/TOhzo+gfxEdMfJ+ibY3pKzg==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.1.0_1779419593870_0.4554831274822366","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@allardy/mcp-oauth-proxy","version":"0.1.1","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.1.1","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"923234da6febb2fd64fef4ed605043a9e98195a9","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.1.1.tgz","fileCount":43,"integrity":"sha512-tXk+m0nDg+6KcL7hEzf4yASRKsbfbkvi5ZLxpULOXVsSd1XDUfrg/ASRpNs9MraFCkczxIfev4mPesMyFPPSyw==","signatures":[{"sig":"MEQCIG3azSIspjRSwoU1Bm+LL0kgdV+xHTUxerKmk3NAjfxzAiBNLcJdOYZL7Qkw+PKr3WzxKh2gzFBFC6R/L8Jg8CFppw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49786},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/8eb13f52e999c46aeac0e38a6a53e92e/allardy-mcp-oauth-proxy-0.1.1.tgz","_integrity":"sha512-tXk+m0nDg+6KcL7hEzf4yASRKsbfbkvi5ZLxpULOXVsSd1XDUfrg/ASRpNs9MraFCkczxIfev4mPesMyFPPSyw==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.1.1_1779423487866_0.18591970501322153","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@allardy/mcp-oauth-proxy","version":"0.1.2","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.1.2","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"fc9e72d624564c7fc061508b8e5749c74c72f8a8","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.1.2.tgz","fileCount":43,"integrity":"sha512-eFawiklgbSojOm4n4iU9kZbINx3qA6d955ww4eiIcqdSL3gYySE7MXmFZ80TjwBkIVHBi/0nd15rHaC7Xlbq8Q==","signatures":[{"sig":"MEUCIQDweha0GKxZ+VbrH7tyeGPEHakQI+1ysXTVzG3sA/yjnQIgENMHovrHS1HSLGb/38U8Y9CDIT9z+t2p9Amkv5tOtzk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":51145},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/f1028ffc356e40341560b1456c1a8202/allardy-mcp-oauth-proxy-0.1.2.tgz","_integrity":"sha512-eFawiklgbSojOm4n4iU9kZbINx3qA6d955ww4eiIcqdSL3gYySE7MXmFZ80TjwBkIVHBi/0nd15rHaC7Xlbq8Q==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.1.2_1779424162789_0.20024181421114173","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@allardy/mcp-oauth-proxy","version":"0.2.0","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.2.0","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"f23d0328c008765a8b10d54eafbd50f325697544","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.2.0.tgz","fileCount":47,"integrity":"sha512-luuP4H1NKOe3X3l3dew0mS7vgzalgo/Nbk1jEfVvv8max9UNJ7ZDOirydHpHHYWdjCWgD4b3QXw8/m4FoINJ9Q==","signatures":[{"sig":"MEUCIAEXCVrq93MOCxs05NgHdOMdEWjHCJBMmLcXcwKN6tp6AiEAlr6lv4f2C012mBxGBfqhiHJRUBuOYlugYI/IMFXY12E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":63819},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.2.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/7666b80b58a1791d0fd26570c244d9d6/allardy-mcp-oauth-proxy-0.2.0.tgz","_integrity":"sha512-luuP4H1NKOe3X3l3dew0mS7vgzalgo/Nbk1jEfVvv8max9UNJ7ZDOirydHpHHYWdjCWgD4b3QXw8/m4FoINJ9Q==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.2.0_1779453662285_0.317688658947227","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@allardy/mcp-oauth-proxy","version":"0.3.0","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.3.0","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"cfc46d00e5c3bae9eaa5cfd93fc5d2e5600635ce","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.3.0.tgz","fileCount":47,"integrity":"sha512-bABHqsTwoa62QXaCBOxOcp70JqBK+Zn4Hmsd5iR8IT86IbkCQ5p0UzCWrvwu13JZ2X8QdDY8PNsMx39DRDX/CA==","signatures":[{"sig":"MEUCIAaUBpUNFXRFtoQoIoBw0mYJ4kZBwaYrqOJFnswaYEHyAiEA3TSItVNVUNnDD+trpX+bSK9AF79CVekPhBzhRpilGvE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67515},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.3.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/32f9fdf23d6d6047fcf073acb2ac5e58/allardy-mcp-oauth-proxy-0.3.0.tgz","_integrity":"sha512-bABHqsTwoa62QXaCBOxOcp70JqBK+Zn4Hmsd5iR8IT86IbkCQ5p0UzCWrvwu13JZ2X8QdDY8PNsMx39DRDX/CA==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.3.0_1779454761081_0.6080947721525887","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@allardy/mcp-oauth-proxy","version":"0.3.1","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.3.1","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"6e35e74dd8aefbf4183f84893124e586bc1c8ca5","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.3.1.tgz","fileCount":47,"integrity":"sha512-3B1f6qT2ezEPvB8MTTNa5d55dsA8yik2v5NkhNLoDG+BmGYEm553/DgcayCa8yCRus3QhDN679rv1ywsxmWQ8g==","signatures":[{"sig":"MEUCIQCI6NwEIwqMZ1WNWW7A5bFmbPsrJ3uITbSWUY5wI+ZcwwIgZ5DKvVk+ZW0TgSTB/umcygxDtCIeih5ponXaWbFgYN4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67887},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.3.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/1cf64b4713c471f6711128d4ccd1bd1b/allardy-mcp-oauth-proxy-0.3.1.tgz","_integrity":"sha512-3B1f6qT2ezEPvB8MTTNa5d55dsA8yik2v5NkhNLoDG+BmGYEm553/DgcayCa8yCRus3QhDN679rv1ywsxmWQ8g==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.3.1_1779455267496_0.535668335579776","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@allardy/mcp-oauth-proxy","version":"0.3.2","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"author":{"name":"Yann Allard"},"license":"MIT","_id":"@allardy/mcp-oauth-proxy@0.3.2","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"bin":{"mcp-oauth-proxy":"dist/index.js"},"dist":{"shasum":"64e0b960eab11aa90465b11beeaadc9e0210b088","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.3.2.tgz","fileCount":47,"integrity":"sha512-WvM1HTeXmpnRGz6hkQy8PTVjp+e6itiIZgcoV+7s6ZcwpLj9EsUySQx7ZM/NF2wkJbU7liXBBSiVRnzz5k+5mQ==","signatures":[{"sig":"MEUCIQC5moZdTj2nUFjQ1SpgU+Eh42QrW2CNjTdNh9UBXFclFwIgQNzwuibPCs/+Zw813kuF5QeZ+Xbcy9gQia4NcE54Gio=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68173},"main":"dist/index.js","type":"module","_from":"file:allardy-mcp-oauth-proxy-0.3.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx watch src/index.ts","fix":"oxfmt --write . && oxlint --fix .","lint":"oxlint .","test":"vitest run","build":"tsc -p tsconfig.json","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json","start":"node dist/index.js","format":"oxfmt --write .","typecheck":"tsc --noEmit -p tsconfig.json","test:watch":"vitest"},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"_resolved":"/tmp/54705c9a5d26e510cdbe9e7ce7a1d54e/allardy-mcp-oauth-proxy-0.3.2.tgz","_integrity":"sha512-WvM1HTeXmpnRGz6hkQy8PTVjp+e6itiIZgcoV+7s6ZcwpLj9EsUySQx7ZM/NF2wkJbU7liXBBSiVRnzz5k+5mQ==","_npmVersion":"10.8.2","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^4.4.3","jose":"^5.9.6","pino":"^9.5.0","express":"^5.2.1","http-proxy-3":"^1.21.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.20.6","oxfmt":"^0.51.0","oxlint":"^1.66.0","vitest":"^2.1.5","supertest":"^7.0.0","typescript":"^6.0.3","@types/node":"^25.6.0","pino-pretty":"^11.3.0","@types/express":"^5.0.6","@types/supertest":"^6.0.2","@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-oauth-proxy_0.3.2_1779457149907_0.18542291188063276","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@allardy/mcp-oauth-proxy","version":"0.3.3","description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"license":"MIT","author":{"name":"Yann Allard"},"bin":{"mcp-oauth-proxy":"dist/index.js"},"type":"module","main":"dist/index.js","publishConfig":{"access":"public"},"dependencies":{"express":"^5.2.1","http-proxy-3":"^1.21.0","jose":"^5.9.6","pino":"^9.5.0","zod":"^4.4.3"},"devDependencies":{"@oxfmt/binding-win32-x64-msvc":"^0.51.0","@oxlint/binding-win32-x64-msvc":"^1.66.0","@types/express":"^5.0.6","@types/node":"^25.6.0","@types/supertest":"^6.0.2","oxfmt":"^0.51.0","oxlint":"^1.66.0","pino-pretty":"^11.3.0","supertest":"^7.0.0","tsx":"^4.20.6","typescript":"^6.0.3","vitest":"^2.1.5"},"optionalDependencies":{"@oxfmt/binding-linux-x64-gnu":"^0.51.0","@oxlint/binding-linux-x64-gnu":"^1.66.0"},"engines":{"node":">=20"},"scripts":{"build":"tsc -p tsconfig.json","dev":"tsx watch src/index.ts","start":"node dist/index.js","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit -p tsconfig.json","lint":"oxlint .","format":"oxfmt --write .","fix":"oxfmt --write . && oxlint --fix .","check":"oxfmt --check . && oxlint . && tsc --noEmit -p tsconfig.json"},"_id":"@allardy/mcp-oauth-proxy@0.3.3","types":"./dist/index.d.ts","_integrity":"sha512-myYhJHaehlJazHCMd4UtAEBzv58L+PccIM+fHPb5P4CT2bDI/AUEQN2UtjCYyoi9d1DAQxXNGV6P0g8uYjwpwQ==","_resolved":"/tmp/6c09ef6892063b5c006a713d718c85e6/allardy-mcp-oauth-proxy-0.3.3.tgz","_from":"file:allardy-mcp-oauth-proxy-0.3.3.tgz","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-myYhJHaehlJazHCMd4UtAEBzv58L+PccIM+fHPb5P4CT2bDI/AUEQN2UtjCYyoi9d1DAQxXNGV6P0g8uYjwpwQ==","shasum":"cd801d83477a4e17a7cd1d36d4496f3882560827","tarball":"https://registry.npmjs.org/@allardy/mcp-oauth-proxy/-/mcp-oauth-proxy-0.3.3.tgz","fileCount":47,"unpackedSize":68697,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDO4MH8cIBUefJmm/RpPa24psqNO4WCh76ubhqZka3RXAiA9oeowTQtA/52M+PZlVSVCSjYs4P1ozD37QnLDFH6VWw=="}]},"_npmUser":{"name":"allardy","email":"yann.allard1@gmail.com"},"directories":{},"maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-oauth-proxy_0.3.3_1779457888793_0.8072298312461608"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-22T03:13:13.770Z","modified":"2026-05-22T13:51:29.133Z","0.1.0":"2026-05-22T03:13:14.001Z","0.1.1":"2026-05-22T04:18:08.041Z","0.1.2":"2026-05-22T04:29:22.931Z","0.2.0":"2026-05-22T12:41:02.444Z","0.3.0":"2026-05-22T12:59:21.231Z","0.3.1":"2026-05-22T13:07:47.653Z","0.3.2":"2026-05-22T13:39:10.068Z","0.3.3":"2026-05-22T13:51:29.031Z"},"author":{"name":"Yann Allard"},"license":"MIT","keywords":["mcp","model-context-protocol","oauth","oidc","proxy"],"description":"OAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only; bring your own OIDC provider.","maintainers":[{"name":"allardy","email":"yann.allard1@gmail.com"}],"readme":"# mcp-oauth-proxy\n\nOAuth bearer-token wrapper for HTTP-transport MCP servers. Resource-server only — bring your own OIDC provider.\n\n**What it does:** Sits in front of any HTTP-transport [Model Context Protocol](https://modelcontextprotocol.io) server and gates traffic on bearer JWTs issued by your OIDC provider (Authentik, Auth0, Keycloak, Okta, Google, etc.). Allows MCP servers that were designed for local trust-the-socket use to be exposed publicly to clients like Claude.ai.\n\n**What it does NOT do:** Issue tokens. That's your OIDC provider's job. This proxy validates tokens; it does not host login UIs or run an OAuth dance with end users.\n\n## How it fits\n\nThe proxy advertises itself as **both** the resource server and the authorization server (RFC 8414). MCP clients (e.g. Claude.ai) discover the proxy's `/.well-known/oauth-authorization-server`, which rewrites `issuer` to match the proxy's URL. The actual `authorize` and `token` endpoints still point at the upstream IdP — clients follow those URLs directly. Token verification uses the upstream's JWKS (tokens carry `iss=upstream`; the JWT verifier is already configured with the upstream issuer URL).\n\n```\n         ┌──────────────────┐         ┌──────────────────┐\n         │   Claude.ai web  │ ──(2)──▶│  OIDC Provider   │\n         │  (or any MCP     │         │  (Authentik etc) │\n         │   client)        │         └──────────────────┘\n         └────────┬─────────┘                  │\n          (1) discovers proxy's                │ issues tokens\n              .well-known/ docs                │ JWKS\n                  │                            │\n                  │ (3) Bearer <jwt>            │\n                  ▼                            │\n         ┌──────────────────┐                  │\n         │  mcp-oauth-proxy │◀─── JWKS ────────┘\n         │  - auth-server   │\n         │    (rewrites      │\n         │     issuer)       │\n         │  - verifies JWT  │\n         │  - allow-list    │\n         │  - rate-limits   │\n         └────────┬─────────┘\n                  │ proxied (no auth headers)\n                  ▼\n         ┌──────────────────┐\n         │   Your MCP       │\n         │   (HTTP)         │\n         └──────────────────┘\n```\n\n## Quick start\n\n### As a Docker container\n\n```bash\ndocker run --rm -p 8080:8080 \\\n  -e OIDC_ISSUER_URL=https://auth.example.com/application/o/my-mcp/ \\\n  -e OIDC_AUDIENCE=my-mcp \\\n  -e RESOURCE_URL=https://mcp.example.com \\\n  -e ALLOW_SUBS=your-user-uuid \\\n  -e MCP_SPAWN_CMD=\"npx -y your-mcp-server --transport http --port 8765\" \\\n  -e MCP_SPAWN_PORT=8765 \\\n  ghcr.io/allardy/mcp-oauth-proxy:latest\n```\n\n### As an npm package (programmatic)\n\n```bash\npnpm add @allardy/mcp-oauth-proxy\n```\n\n```ts\nimport { buildApp } from '@allardy/mcp-oauth-proxy'\n\nconst app = buildApp({\n  /* ...same shape as env vars... */\n})\napp.listen(8080)\n```\n\n## Configuration\n\n| Variable               | Required     | Description                                                                                                                                                                                                                                                                       |\n| ---------------------- | ------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `OIDC_ISSUER_URL`      | yes          | OIDC discovery URL (anything ending in / where /.well-known/openid-configuration resolves).                                                                                                                                                                                       |\n| `OIDC_AUDIENCE`        | yes          | Expected `aud` claim.                                                                                                                                                                                                                                                             |\n| `RESOURCE_URL`         | yes          | This proxy's public URL. Used in the protected-resource discovery doc.                                                                                                                                                                                                            |\n| `ALLOW_SUBS`           | one of these | Comma-separated allow-list of token `sub` values.                                                                                                                                                                                                                                 |\n| `ALLOW_EMAILS`         |              | Comma-separated allow-list of token `email` values.                                                                                                                                                                                                                               |\n| `ALLOW_GROUPS`         |              | Comma-separated allow-list of token `groups` claim values.                                                                                                                                                                                                                        |\n| `MCP_UPSTREAM_URL`     | xor          | Existing HTTP MCP to proxy to.                                                                                                                                                                                                                                                    |\n| `MCP_SPAWN_CMD`        | xor          | Command to spawn as a child process.                                                                                                                                                                                                                                              |\n| `MCP_SPAWN_PORT`       | with cmd     | Port the spawned MCP listens on.                                                                                                                                                                                                                                                  |\n| `PORT`                 | no           | Default 8080.                                                                                                                                                                                                                                                                     |\n| `LOG_LEVEL`            | no           | `trace` to `fatal`. Default `info`.                                                                                                                                                                                                                                               |\n| `RATE_LIMIT_RPM`       | no           | Per-`sub` rate limit. Default 60.                                                                                                                                                                                                                                                 |\n| `CORS_ALLOW_ORIGINS`   | no           | Comma-separated allowed browser origins for CORS. Default: `https://claude.ai,https://claude.com`. Use `*` to allow any origin.                                                                                                                                                   |\n| `STATIC_CLIENT_ID`     | no           | OIDC providers that don't support open DCR can use this pair. The proxy hosts a `/oauth/register` endpoint that always returns these credentials to any caller, and the `oauth-authorization-server` discovery doc advertises this endpoint. Useful for Authentik, etc.           |\n| `STATIC_CLIENT_SECRET` | no           | See `STATIC_CLIENT_ID`. Both must be set together or both left unset.                                                                                                                                                                                                             |\n| `MCP_UPSTREAM_PATH`    | no           | Optional path on the upstream. All non-discovery, non-healthz, non-oauth-register requests are forwarded to `${MCP_UPSTREAM_URL}${MCP_UPSTREAM_PATH}` (or the spawned upstream URL). Use when the upstream MCP listens at a sub-path like `/mcp` but the proxy is exposed at `/`. |\n| `SCOPES_SUPPORTED`     | no           | Comma-separated list of OAuth scopes the resource server supports. Advertised in both the protected-resource and auth-server discovery docs. Defaults to `openid,profile,email,offline_access`.                                                                                   |\n\n## Working with OIDC providers that don't support DCR\n\nSome OIDC providers (including Authentik 2025.10.x) don't advertise a `registration_endpoint` in their discovery doc and don't support open Dynamic Client Registration (RFC 7591). Claude.ai's \"Add custom connector\" flow requires DCR — if the discovery doc doesn't advertise `registration_endpoint`, it silently gives up.\n\n**Workaround:** pre-create an OIDC application in your provider (Authentik: Applications → Providers → OAuth2/OpenID Connect), then configure the proxy with the resulting client_id and client_secret:\n\n```bash\nSTATIC_CLIENT_ID=your-client-id\nSTATIC_CLIENT_SECRET=your-client-secret\n```\n\nThe proxy will:\n\n1. Host `POST /oauth/register` — returns your pre-configured credentials to any caller (no validation of the request body beyond parsing it).\n2. Inject `registration_endpoint` into the proxy's `/.well-known/oauth-authorization-server` discovery doc (with `issuer` rewritten to the proxy's own URL) so clients see DCR as available.\n\nThe upstream provider's redirect_uri whitelist still governs which callbacks are accepted at `/authorize` time, so adding only the real Claude.ai callback URL to the whitelist is the correct security boundary.\n\n**Note on issuer rewriting:** The proxy rewrites `issuer` in the `/.well-known/oauth-authorization-server` response to its own `RESOURCE_URL`. This satisfies RFC 8414's requirement that the `issuer` value matches the URL from which the metadata was fetched. The `authorize` and `token` endpoint URLs remain pointing at the upstream IdP — MCP clients follow those directly. JWT tokens still carry the upstream's `iss` claim and the proxy's JWT verifier is configured accordingly.\n\n## Security model\n\n- **Resource-server only** — does not initiate OAuth flows or maintain user state.\n- **Allow-list gating** — even after JWT verification, the request is rejected unless the token's `sub`, `email`, or one of its `groups` matches a configured list.\n- **Per-`sub` rate limiting** — default 60 req/min as defense-in-depth.\n- **Audit log** — every authenticated request is logged at info level (sub, method, path, ts).\n\n**Suitable for:** personal deployments, small-team MCPs, internal tools.\n**Not suitable for:** multi-tenant SaaS — allow-list and rate-limit are per-process; use a real authorization service for that.\n\n## Examples\n\n- [Samsung Health MCP behind Authentik](examples/samsung-health-with-authentik.md)\n- [Any MCP behind Auth0](examples/generic-with-auth0.md)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}