{"_id":"@arc-mcp/xsuaa-auth","_rev":"11-c3d16cc36a9b11607b5d39c0b1ed4502","name":"@arc-mcp/xsuaa-auth","dist-tags":{"latest":"1.1.0"},"versions":{"0.1.0":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.0","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.0","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"553501b34ac41d1ffb484059b5e0c4af28a1b98b","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.0.tgz","fileCount":75,"integrity":"sha512-NjLXYaR3Gj9UBceCTinhoEKUnXgg7D/QF+kf7cL0AN6moeP8lKI+whlRAWe7Fw2IaHG/+XSHHI2opRkMnbJCzQ==","signatures":[{"sig":"MEUCIFWsw5OBpF2inxTozCmoC0yQoGiQ2JL1Ex01Fbnf3crGAiEA5RbPYHbeowioU1pxzJGSVptrOxYBCYhdE+uYly7FYEE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272339},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"db090904cf104af13f383c2d118ccfcc26a21ad0","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"marianfoo","email":"marianbsp@gmail.com"},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"10.9.4","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.21.1","dependencies":{"@sap/xssec":"^4","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^3.0.0","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^5.8.0","@types/node":"^22.10.0","lint-staged":"^17.0.7","@biomejs/biome":"^1.9.4","@types/express":"^5.0.0","@types/supertest":"^6.0.3","@vitest/coverage-v8":"^3.0.0","@arethetypeswrong/cli":"^0.18.3","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.0_1781724609805_0.24274574657384118","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.2","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.2","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"ac4a1a5ade4e8041b309b5ad3d9ad24b1d8d253a","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.2.tgz","fileCount":75,"integrity":"sha512-f/b0b18LR4AHn3heoYY870gag0vZ5F89TW3FPpFrEdvZfT6KDp/gMU8l4GTUoSu9ix6xreBMACtxab0vMCwYLA==","signatures":[{"sig":"MEUCIHvtyUoFHT/prssjCQxxTZWJTdHeDpqY+bLpVFd9MK3aAiEA3Yj6qfLDfjnvrAWrDNRn6zaX3w4a9RaURQhRePyjnAc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":273684},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"10f83ff0d4241efee5c70e354146cc0188c503cd","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.22.3","dependencies":{"@sap/xssec":"^4","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^3.0.0","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^5.8.0","@types/node":"^22.10.0","lint-staged":"^17.0.7","@biomejs/biome":"^1.9.4","@types/express":"^5.0.0","@types/supertest":"^6.0.3","@vitest/coverage-v8":"^3.0.0","@arethetypeswrong/cli":"^0.18.3","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.2_1781730926243_0.8947400834643369","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.3","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.3","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"bf46973068caeeecb54e32cb412c6100b6000659","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.3.tgz","fileCount":79,"integrity":"sha512-So/l1wioLluhXt96OmSrmFZ9qIpKMEWJWHBXd/cdKSWr27wx5zFnCvLd355g+C5WFWSbf55s5IPH4BDY4Yrl+Q==","signatures":[{"sig":"MEQCIBroSMUnS0ly5WvGIfyzNWs4NA2sX+AgCY8+s9qC7bN5AiB2v6Hbgqod+cNNyIHRJQcFXs/DPgZyRsYjG9uKMywV8w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":288686},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"96ee6eeebbc9158d86a2ddbf7ab37e0bfd0bbfca","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.22.3","dependencies":{"@sap/xssec":"^4","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^6.0.3","@types/node":"^22.10.0","lint-staged":"^17.0.7","@biomejs/biome":"^2.5.0","@types/express":"^5.0.0","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.1.9","@arethetypeswrong/cli":"^0.18.3","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.3_1781769729030_0.2062138042872539","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.4","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.4","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"ae313da59b1a32eb441a34013081e882b8ba8b21","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.4.tgz","fileCount":79,"integrity":"sha512-f2Dhh2xAy8Zv+PFVy5tnPcFJYSffhb+0BYgY9gFErYM4ipve6NuDE4kyvBBGiGk7jwKDl68NTi572d0n/oJsMg==","signatures":[{"sig":"MEUCIQC0RaONJtQHeybgD2gpRIPYVq5v+fLihiNkgBOaTefzKAIgLUGi6osNmEFqGddod2FgfxJbICwvTuI9hyY5qbdwma8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":294584},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"745082a4b34a3c67bfb9bec762d3a5be5de48d63","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.0","dependencies":{"@sap/xssec":"^4","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^6.0.3","@types/node":"^22.20.0","lint-staged":"^17.0.8","@biomejs/biome":"^2.5.0","@types/express":"^5.0.0","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.1.9","@arethetypeswrong/cli":"^0.18.3","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.4_1782508024251_0.5141030407176299","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.5","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.5","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"e6a6ddb580355604b0e7aa7efdd8cdda9feb538e","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.5.tgz","fileCount":79,"integrity":"sha512-ud5tumVSaKz/vBcv/UhYgqgDllpBYDBq3G5BY3c7esOrk5CSg4Toq0125aqgcObn9jP13bowzzuQkSB3xt0RMQ==","signatures":[{"sig":"MEYCIQD+pCjOLITXK8keutU2XcwbKs2Mr70GIhKRZJ+jpzHmgwIhAPeObFOQHG42Lk2cmrh8i48zlEM+NSo8+0VFIbPStVzv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":308005},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"5b5c5d094bf25b5660a0db76c57acc5e025be802","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.0.8","@biomejs/biome":"^2.5.3","@types/express":"^5.0.0","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.5_1784301479807_0.2169834940365276","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.6","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.6","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"77380cb9481693e757cc4bd451f49b6428b50615","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.6.tgz","fileCount":79,"integrity":"sha512-1SUSWGhhpfgxcnKAWkKWDFjkV9289GGMxha1zZwUbkcgSxoSV1aOQY1vk1JDy0xIoL4Zc9tS/LHq6CFDFuDqjw==","signatures":[{"sig":"MEQCIB43Q54mH1ekLFxR1jo21zIaIORG3xjJ0nKk4J/TBtGaAiBOdZ2QzoZtL8j8F4NmA+wEB82VL5+5CgyHljMu6ruP+w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":313960},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"1a53b68fbf9814afa86caf93a8d767760f12eb78","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.0.8","@biomejs/biome":"^2.5.3","@types/express":"^5.0.0","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.6_1784504262827_0.8872058139970338","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@arc-mcp/xsuaa-auth","version":"0.1.8","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@0.1.8","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"288b265c88286ae01ac62c634f16811685daacc1","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-0.1.8.tgz","fileCount":79,"integrity":"sha512-ufRgPNLH3zAfzObLqfau8JNzfvowA0qSmY6i+lk1HOJFUVopN4gYtbpZqwt6fBBQaJobjno/w7QkXd0YTH3tig==","signatures":[{"sig":"MEYCIQD+mTuP1QusxCRKp1sMuf7Hjb3rvfKpHYEbH9lkT8sBAgIhAMmsVm2mqBq1SHz1NMzOndOu/hJ0MlgDrZLa0oSP7ilj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":322706},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"43eef024dfa1ec28d86d371ed1aa65e696689e40","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.0.8","@biomejs/biome":"^2.5.3","@types/express":"^5.0.0","@types/supertest":"^7.2.0","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_0.1.8_1784521831464_0.9702895892223762","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"@arc-mcp/xsuaa-auth","version":"1.0.0","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@1.0.0","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"80305bbd9f0893c12767ae8364c21eb30a624240","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-1.0.0.tgz","fileCount":79,"integrity":"sha512-2586hvCp5slpvWsHIvPSjHDw0LUqGCcG0tVtEPYPq+W6coifv2/z+WvEWpLPQSLS23BLfFjxHKW5SdgV8zs3aw==","signatures":[{"sig":"MEUCIAwI15TkzdXk7OhAzHcC352b3y6nCj7IvpujlyMeSEEbAiEA96o6IkXD3dnk+3ST0V5IYUSUqlfO8shhRPVKbjPG3OU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":322954},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"424d823852d471ce0418ae324cf307511f30d437","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.2","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.0","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.1.0","@biomejs/biome":"^2.5.4","@types/express":"^5.0.0","@types/supertest":"^7.2.1","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_1.0.0_1784826119488_0.8924250895729766","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@arc-mcp/xsuaa-auth","version":"1.0.1","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@1.0.1","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"b08b6ca91255ef5c08f5118ba8e515930cbe4089","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-1.0.1.tgz","fileCount":79,"integrity":"sha512-5fTTGrOj4giskBARFH5IpPU1efu0dUO28G/n6ojxaXGRHXwQcpBgccGG/oPZMg426xc1bGPZFgOi1P5UixE/Rw==","signatures":[{"sig":"MEUCIQC5a140WkJW7uxnjIx9dKFcRaoZFHypU0NwxDO0ZOz7QwIgMCNyscbqT7TEAriEUXjoeLWZsecvKznKfnPTsJVG57k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":323270},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"55aa43e9f5955179434b360ce387d4bebc653d39","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.8.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.4","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.22","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.2.0","@biomejs/biome":"^2.5.5","@types/express":"^5.0.0","@types/supertest":"^7.2.1","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_1.0.1_1785130619994_0.6259459279286803","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@arc-mcp/xsuaa-auth","version":"1.0.2","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"author":{"name":"Marian Zeis"},"license":"MIT","_id":"@arc-mcp/xsuaa-auth@1.0.2","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"b9c81f6464c47545443e3a35310f2f27d2fd9402","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-1.0.2.tgz","fileCount":79,"integrity":"sha512-TgHECyPDY/AETe7B5BqM2zr+LNSOG0mzKPV4xKEsfkQrKr7z8WutrpB22M4ZGTP6A2SvW3kaorLFAaJcRuYg6w==","signatures":[{"sig":"MEQCIC9UeHW77gZBm3x0C4JMHGzlH994UBZtXdjadofmjn8VAiBTmkw3fBpaLvlfcEn75D/KLJpwyQtAIaPDO8QJdwSl8w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":323572},"type":"module","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"461627cfa889820d0db2aabd7869eed6a7c6387d","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"@sap/xssec":"^4.13.3","@sap-cloud-sdk/connectivity":"^4.8.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.8","husky":"^9.1.7","vitest":"^4.1.9","express":"^5.2.1","publint":"^0.3.23","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.1","lint-staged":"^17.3.0","@biomejs/biome":"^2.5.7","@types/express":"^5.0.0","@types/supertest":"^7.2.1","@vitest/coverage-v8":"^4.1.10","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/xsuaa-auth_1.0.2_1786338726242_0.376700966178906","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"_id":"@arc-mcp/xsuaa-auth@1.1.0","bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"dist":{"shasum":"c4f13fe49b994f96ad0c85b4efd60996d6fb0007","tarball":"https://registry.npmjs.org/@arc-mcp/xsuaa-auth/-/xsuaa-auth-1.1.0.tgz","fileCount":95,"integrity":"sha512-vntaNwb4vFqZw3QB7ZAZJtrdbuc/AB6csa18Ie617CUK96+v8XwgvXetA9tQaW4eWI7+Cp6dW158gwiZuXhk8g==","signatures":[{"sig":"MEYCIQDZ9zua3nXwVO6lJ53iRc2uAr4V8CMWFUInXDDSPS+ZIAIhAOJJGonGD/zmsS+6d2Yb7fu65ExIVfGQRK9Xl2yZHEqm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHr3P1rFkLYNthocs6if8QnWymyh+ON1oQl1TRAJXixCAiBh2PxF1OzUjFBdNwiDJGokf4FyVI1eGsj96ynjFDl66Q=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@arc-mcp%2fxsuaa-auth@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":362027},"name":"@arc-mcp/xsuaa-auth","type":"module","author":{"name":"Marian Zeis"},"engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"./btp":{"types":"./dist/btp.d.ts","default":"./dist/btp.js"},"./package.json":"./package.json"},"gitHead":"1e92a059a3b80341907eece82826c997eb64a1d3","license":"MIT","scripts":{"lint":"biome check .","test":"vitest run","build":"tsc","format":"biome format --write .","prepare":"husky || true","coverage":"vitest run --coverage","lint:fix":"biome check --write .","typecheck":"tsc --noEmit && tsc --noEmit -p tests/types/tsconfig.json","test:watch":"vitest","check:exports":"publint && attw --pack . --profile esm-only","prepublishOnly":"npm run build"},"version":"1.1.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:2fb3af74-7a0b-4cfb-8141-782e57094a06"}},"homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"_npmVersion":"11.11.1","description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","directories":{},"lint-staged":{"*.{ts,js,json}":"biome check --write --no-errors-on-unmatched"},"maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"@sap/xssec":"^4.15.0","@sap-cloud-sdk/connectivity":"^4.9.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"jose":"^6.2.12","husky":"^9.1.7","vitest":"^5.0.0","express":"^5.2.1","publint":"^0.3.24","supertest":"^7.2.2","typescript":"^7.0.2","@types/node":"^22.20.2","lint-staged":"^17.5.1","@biomejs/biome":"^2.5.13","@types/express":"^5.0.0","@types/supertest":"^7.2.1","@vitest/coverage-v8":"^5.0.0","@arethetypeswrong/cli":"^0.18.5","@modelcontextprotocol/sdk":"^1.28.0"},"peerDependencies":{"jose":">=5 <7","express":"^5.0.1","@modelcontextprotocol/sdk":">=1.18.2 <2"},"peerDependenciesMeta":{"jose":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/xsuaa-auth_1.1.0_1789630719500_0.6896445190640472"}}},"time":{"created":"2026-06-17T19:30:09.594Z","modified":"2026-09-17T07:38:39.912Z","0.1.0":"2026-06-17T19:30:09.929Z","0.1.2":"2026-06-17T21:15:26.460Z","0.1.3":"2026-06-18T08:02:09.226Z","0.1.4":"2026-06-26T21:07:04.405Z","0.1.5":"2026-07-17T15:18:00.023Z","0.1.6":"2026-07-19T23:37:42.991Z","0.1.8":"2026-07-20T04:30:31.587Z","1.0.0":"2026-07-23T17:01:59.645Z","1.0.1":"2026-07-27T05:37:00.159Z","1.0.2":"2026-08-10T05:12:06.377Z","1.1.0":"2026-09-17T07:38:39.604Z"},"bugs":{"url":"https://github.com/arc-mcp/xsuaa-auth/issues"},"author":{"name":"Marian Zeis"},"license":"MIT","homepage":"https://github.com/arc-mcp/xsuaa-auth#readme","keywords":["mcp","model-context-protocol","sap","btp","xsuaa","oauth","oauth2","authentication","principal-propagation"],"repository":{"url":"git+https://github.com/arc-mcp/xsuaa-auth.git","type":"git"},"description":"XSUAA / OAuth authentication + BTP principal propagation for Model Context Protocol (MCP) servers built on Express and @modelcontextprotocol/sdk.","maintainers":[{"name":"marianfoo","email":"marianbsp@gmail.com"}],"readme":"# @arc-mcp/xsuaa-auth\n\n**XSUAA / OAuth authentication + SAP BTP principal propagation for [Model Context Protocol](https://modelcontextprotocol.io) servers** built on Express and [`@modelcontextprotocol/sdk`](https://github.com/modelcontextprotocol/typescript-sdk).\n\n[![CI](https://github.com/arc-mcp/xsuaa-auth/actions/workflows/ci.yml/badge.svg)](https://github.com/arc-mcp/xsuaa-auth/actions/workflows/ci.yml)\n[![CodeQL](https://github.com/arc-mcp/xsuaa-auth/actions/workflows/codeql.yml/badge.svg)](https://github.com/arc-mcp/xsuaa-auth/actions/workflows/codeql.yml)\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/arc-mcp/xsuaa-auth/badge)](https://scorecard.dev/viewer/?uri=github.com/arc-mcp/xsuaa-auth)\n[![npm](https://img.shields.io/npm/v/@arc-mcp/xsuaa-auth.svg)](https://www.npmjs.com/package/@arc-mcp/xsuaa-auth)\n\nIt gives an MCP server the SAP-native client→server auth stack: an **XSUAA OAuth proxy provider**, a stateless **RFC 7591 Dynamic Client Registration** store (HMAC-signed `client_id`s, restart-resilient), the OAuth-state callback codec that works around XSUAA's un-encoded `+` in `state`, a chained bearer verifier (**XSUAA → OIDC → API-key**, each optional), and a thin `setupHttpAuth` facade. A separate [`./btp`](#principal-propagation-btp) entrypoint adds **per-user principal propagation** via the BTP Destination Service + Cloud Connector.\n\nTwo API layers, same package: a **plug-and-play facade** for the common flow, and the **building blocks** it composes for full control.\n\n> Extracted from [arc-1](https://github.com/marianfoo/arc-1)'s production auth stack and designed so arc-1, calmcp, and LISA can adopt it with a minimal diff. The full design rationale is frozen in [`docs/SPEC.md`](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/SPEC.md) and [`docs/RESEARCH.md`](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/RESEARCH.md).\n\n---\n\n## Install\n\n```bash\nnpm install @arc-mcp/xsuaa-auth\n```\n\nESM-only, Node **>= 22**. You also need these **peer dependencies** (the package shares the host's Express + MCP SDK instances rather than bundling its own):\n\n| Peer | Range | Required? |\n|------|-------|-----------|\n| [`@modelcontextprotocol/sdk`](https://www.npmjs.com/package/@modelcontextprotocol/sdk) | `>=1.18.2 <2` | **yes** — `1.18.2` is the first version exposing `mcpAuthRouter({ resourceServerUrl })` |\n| [`express`](https://www.npmjs.com/package/express) | `^5.0.1` | **yes** — the SDK hard-depends on Express 5; v4 cannot coexist with its router |\n| [`jose`](https://www.npmjs.com/package/jose) | `>=5 <7` | **optional** — only for the OIDC verifier; lazy-imported, so non-OIDC consumers can skip it |\n\n```bash\nnpm install @modelcontextprotocol/sdk express\nnpm install jose            # only if you use createOidcVerifier / AuthOptions.oidc\n```\n\n`@sap/xssec` and `@sap-cloud-sdk/connectivity` are regular dependencies and install automatically.\n\n---\n\n## Quickstart\n\n### Layer 1 — the `setupHttpAuth` facade (plug-and-play)\n\nThe facade composes the standard XSUAA + DCR + callback + bearer flow and returns the bearer middleware for your `/mcp` route. On Cloud Foundry, `loadXsuaaCredentials()` and `resolveAppUrl()` read the bound XSUAA service and the public route straight from the environment — no hand-parsed binding.\n\n```ts\nimport express from 'express';\nimport { setupHttpAuth, loadXsuaaCredentials, resolveAppUrl } from '@arc-mcp/xsuaa-auth';\n\nconst app = express();\napp.use(express.json());\napp.use(express.urlencoded({ extended: true }));\n\nconst bearer = setupHttpAuth(\n  app,\n  {\n    apiKeys: process.env.API_KEYS,                 // string | ApiKeyEntry[]\n    xsuaa: {\n      credentials: loadXsuaaCredentials(),         // from VCAP_SERVICES\n      appUrl: resolveAppUrl(process.env, { publicUrlEnvVar: 'PUBLIC_URL', port: 8080 }),\n      clientIdPrefix: 'myapp-',\n      resourceName: 'My MCP Server',\n      // requiredScopes: ['Viewer'],               // enforced via requireBearerAuth\n    },\n    oidc: { issuer: process.env.OIDC_ISSUER!, audience: process.env.OIDC_AUDIENCE! },\n    allowedOrigins: ['https://claude.ai'],          // CORS for browser MCP clients\n    required: true,                                 // fail closed if nothing is configured\n  },\n  logger,                                           // optional Logger (default: no-op)\n);\n\n// Mount your MCP transport behind the returned middleware.\napp.all('/mcp', bearer!, myMcpHandler);\n```\n\nWhat the facade does in XSUAA mode: applies CORS (if `allowedOrigins` set) → builds the chained verifier → creates the XSUAA OAuth provider → mounts the pattern-gated `/authorize` `ensureRedirectUri` shim, the `/oauth/callback` proxy, and the SDK `mcpAuthRouter` (discovery + `authorize`/`token`/`register`/`revoke`) → returns `requireBearerAuth`. With **no** `xsuaa` block (API-key/OIDC only) it returns bearer middleware **without** mounting the OAuth router. With **no** method configured it throws when `required: true`, else logs a loud warning and returns `undefined` (open).\n\nIt deliberately sets **no restrictive `Cross-Origin-Opener-Policy`** — popup-based OAuth (Copilot Studio, claude.ai) breaks under `COOP: same-origin`. Broader hardening (helmet CSP/HSTS) stays yours to add.\n\n### Layer 2 — building blocks (full control)\n\nWhen you orchestrate the HTTP server yourself (arc-1, LISA), call the same primitives the facade uses:\n\n```ts\nimport {\n  createXsuaaOAuthProvider,\n  createXsuaaTokenVerifier,\n  createOidcVerifier,\n  createApiKeyVerifier,\n  createChainedTokenVerifier,\n  createOAuthCallbackHandler,\n  StatelessDcrClientStore,\n  OAuthStateCodec,\n  validateRedirectUri,\n} from '@arc-mcp/xsuaa-auth';\nimport { requireBearerAuth } from '@modelcontextprotocol/sdk/server/auth/middleware/bearerAuth.js';\nimport { mcpAuthRouter } from '@modelcontextprotocol/sdk/server/auth/router.js';\n\n// 1. The XSUAA OAuth provider also hands you the DCR store + state codec.\nconst { provider, clientStore, stateCodec } = createXsuaaOAuthProvider(credentials, appUrl, {\n  clientIdPrefix: 'myapp-',\n  dcrSigningSecret: process.env.DCR_SIGNING_SECRET, // stabilizes client_ids across restarts\n});\n\n// 2. Chain the verifiers (XSUAA → OIDC → api-key; each optional).\n//    Pass expandScopes to EACH sub-verifier — that's the layer that applies it\n//    (the chain does not re-apply it; see the note below). The chain's own\n//    `{ expandScopes }` only configures the api-key verifier it builds internally.\nconst verifier = createChainedTokenVerifier(\n  { apiKeys: process.env.API_KEYS },\n  createXsuaaTokenVerifier(credentials, { expandScopes }),\n  createOidcVerifier(issuer, audience, { algorithms: ['RS256', 'ES256', 'PS256'], expandScopes }),\n  { expandScopes },\n);\n\n// 3. Wire it onto your app exactly how you need (callback proxy, /authorize shim, router…).\napp.get('/oauth/callback', createOAuthCallbackHandler(stateCodec, clientStore, { logger }));\napp.use(mcpAuthRouter({ provider, issuerUrl, baseUrl, resourceServerUrl, scopesSupported, resourceName }));\napp.all('/mcp', requireBearerAuth({ verifier: { verifyAccessToken: verifier }, resourceMetadataUrl }), myMcpHandler);\n```\n\nEach verifier accepts an optional injected **`expandScopes`** policy hook (default identity), applied **exactly once** by the sub-verifier that produces the `AuthInfo`. `createChainedTokenVerifier` does **not** re-apply it on top of a sub-verifier's result (so a non-idempotent expander runs once, not twice) — it only uses the hook for the api-key verifier it builds from `config.apiKeys`. arc-1 passes its `authz/policy` function so `AuthInfo` carries expanded scopes; other consumers omit it. The package owns **no** scope/tool policy — it's injected, never owned.\n\nEach verifier also accepts **`acceptedScopes`** (default the arc-1 set `['read','write','data','sql','transports','git','admin']`) — the scope-name allowlist applied to a token's claims. Override it (e.g. `['Viewer']`) when your scopes differ, or, via the facade, set `xsuaa.scopesSupported` (which the facade threads to both verifiers).\n\n`createOidcVerifier` additionally accepts **`fallbackScopes`** (default `[]`, **fail closed**) — the scopes granted when a *verified* OIDC token carries no accepted scope (no `scope`/`scp` claim, or claims that match none of `acceptedScopes`). The empty default means an IdP misconfigured to drop scope claims grants **no** access rather than silently falling back to read-only. Opt into the legacy read-only behavior with `fallbackScopes: ['read']` (via the facade, `oidc.fallbackScopes`). It is not run through `expandScopes`.\n\n### Verified user attributes (optional building block)\n\n`createXsuaaTokenVerifier` accepts `userAttributeNames` and `requireUserToken` for applications\nthat authorize individual user principals with XSUAA attributes. Omitting both options preserves\nthe existing verifier behavior and `AuthInfo` shape. This is not enabled by `setupHttpAuth`.\n\n```ts\nconst verify = createXsuaaTokenVerifier(credentials, {\n  userAttributeNames: ['arc1_targets'],\n  requireUserToken: true,\n});\nconst authInfo = await verify(accessToken);\n// authInfo.extra.xsuaaUserAttributes: { arc1_targets: ['A4H/001', 'A4H/100'] }\n// authInfo.extra.xsuaaUserAttributeStatus: { arc1_targets: 'valid' }\n```\n\nOnly allowlisted attributes from the successfully validated SAP security context are copied.\nThe arrays and records are frozen; missing, malformed, and over-limit values carry distinct safe\nstatus codes. Target syntax and application policy stay in the consumer. Do not request an OAuth\nscope named `user_attributes` to activate this feature.\n\n`requireUserToken` rejects machine or unknown principals with the exported\n`XsuaaUserTokenRequiredError`. It extends the MCP SDK's `InsufficientScopeError`, so\n`requireBearerAuth` returns **403** with this package's `forbidden` wire code, not an\n`insufficient_scope` step-up challenge; ordinary `InvalidTokenError` remains\n**401**. A custom adapter can instead map its stable `XSUAA_USER_TOKEN_REQUIRED` code to a generic\n403. A machine principal cannot satisfy this policy by requesting more scopes. Do not parse error\nmessages or retry another authentication method after this terminal error; the package's chain\npreserves the terminal decision in either JWT verifier slot. It unwraps own `Error.cause` wrappers\nand normalizes errors from separately loaded package copies to the fixed local error. Ordinary\nmissing-scope challenges remain `insufficient_scope`. The tested TypeScript SDK clients do not\nretry OAuth on `forbidden`; other MCP clients may recover on any 403 and need separate validation.\n\nThe chain still tries other verifiers after an ordinary validation/JWKS failure. Do not configure\nan alternative verifier that accepts the same XSUAA tokens with a weaker principal policy. For a\nuser-only XSUAA route, use the configured XSUAA verifier directly. Attribute extraction alone is\nnot proof of a user principal or application permission; enforce the required local scopes too.\nSee [the attribute/principal contract and live-evidence gates](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/USER-ATTRIBUTES.md).\n\n---\n\n## `AuthOptions`\n\nThe facade's configuration object. All fields are optional except where noted.\n\n| Field | Type | Default | Notes |\n|-------|------|---------|-------|\n| `apiKeys` | `string \\| ApiKeyEntry[]` | — | A single static key, or `[{ key, scopes?, clientId? }]`. Matched in constant time. **A bare string key grants `scopes: []`** — it authenticates but fails any `requiredScopes`; use `[{ key, scopes: [...] }]` to grant scopes. |\n| `xsuaa` | `object` | — | Present ⇒ XSUAA OAuth proxy is mounted (see sub-fields below). Omit for API-key/OIDC-only. |\n| `xsuaa.credentials` | `XsuaaCredentials` | **required** | `{ url, clientid, clientsecret, xsappname, uaadomain, verificationkey? }`. Use `loadXsuaaCredentials()`. |\n| `xsuaa.appUrl` | `string` | **required** | Public URL the OAuth metadata advertises. Use `resolveAppUrl()`. |\n| `xsuaa.clientIdPrefix` | `string` | `'mcp-'` | Prefix for issued DCR `client_id`s — set a per-deployment value. |\n| `xsuaa.dcrKdfLabel` | `string` | `'mcp-dcr/v1'` | Domain-separation label for DCR `client_id` signing. Bumping it revokes all issued client_ids. |\n| `xsuaa.stateKdfLabel` | `string` | `'mcp-oauth-state/v1'` | Domain-separation label for OAuth-state tokens. |\n| `xsuaa.resourceName` | `string` | SDK default | `resource_name` in the protected-resource metadata. |\n| `xsuaa.scopesSupported` | `string[]` | — | Advertised in OAuth metadata. **Also threaded to the XSUAA + OIDC verifiers as `acceptedScopes`** — set it to your own scope names (e.g. `['Viewer']`) so non-arc-1 scopes aren't filtered out of verified tokens. |\n| `xsuaa.requiredScopes` | `string[]` | — | Enforced via the SDK's `requireBearerAuth({ requiredScopes })`. |\n| `xsuaa.redirectUriPatterns` | `readonly string[]` | `XSUAA_DEFAULT_REDIRECT_URI_PATTERNS` | Allowlist for the `/authorize` shim. **Must mirror** your `xs-security.json` `oauth2-configuration.redirect-uris`. |\n| `xsuaa.defaultRedirectUris` | `readonly string[]` | `XSUAA_DEFAULT_REDIRECT_URIS` | Pre-registered URIs (Claude, Cursor, VS Code, MCP Inspector ship by default). |\n| `xsuaa.dcrTtlSeconds` | `number` | `2592000` (30d) | DCR `client_id` lifetime. `0` disables expiry (recommended for clients that don't auto-re-register on `invalid_client`). |\n| `xsuaa.stateTtlSeconds` | `number` | `600` | OAuth-state token lifetime. `0` disables expiry. |\n| `xsuaa.dcrSigningSecret` | `string` | XSUAA `clientsecret` | Dedicated HMAC secret for DCR `client_id`s — set a ≥32-byte value so a `clientsecret` rotation doesn't invalidate cached client_ids. |\n| `xsuaa.callbackUrl` | `string` | `${appUrl}/oauth/callback` | This server's own OAuth callback URL sent to XSUAA as the redirect_uri (issue #214 callback proxy). Must match a `redirectUriPatterns` entry. |\n| `oidc` | `object` | — | `{ issuer, audience, clockToleranceSec?, algorithms?, scopeClaim?, acceptedScopes?, fallbackScopes? }`. Lazy-imports `jose`. `algorithms` defaults to `['RS256','ES256','PS256']`; `scopeClaim` overrides the primary scope-claim name (default `scope`); `acceptedScopes` is the scope-name allowlist for **OIDC-only** deployments with custom scope names (defaults to `xsuaa.scopesSupported`, else the arc-1 set); `fallbackScopes` (default `[]`, fail closed) is the scope set granted when a verified token carries no accepted scope — set `['read']` for legacy read-only fallback. |\n| `allowedOrigins` | `string[]` | — | Exact-match CORS allowlist (with `credentials`) for browser MCP clients. Unset = no CORS. |\n| `required` | `boolean` | `false` | `true` ⇒ throw if no method configured; `false` ⇒ warn + return `undefined` (open). |\n| `expandScopes` | `(scopes: string[]) => string[]` | identity | Injected scope-expansion policy, applied by every verifier. |\n\n`setupHttpAuth(app, options, logger?)` returns the `/mcp` bearer `RequestHandler`, or `undefined` when no method is configured and `required` is falsy.\n\n---\n\n## Principal propagation (`./btp`)\n\nThe `./btp` entrypoint maps the authenticated MCP user to their own SAP identity via the BTP Destination Service + Cloud Connector. The handoff from the auth layer is just the **raw, already-verified bearer JWT** (`authInfo.token`).\n\n```ts\nimport {\n  listDestinationsAtLevel,\n  lookupDestinationWithUserToken,\n  lookupDestinationWithUserTokenUncached,\n  parseVCAPServices,\n  resolveBTPDestination,\n} from '@arc-mcp/xsuaa-auth/btp';\n\n// Technical (shared) destination — no per-user identity:\nconst { url, username, password, client, proxy } = await resolveBTPDestination('SAP_TRIAL', logger);\n\n// Per-user principal propagation — pass the verified user JWT:\nconst btpConfig = parseVCAPServices(process.env)!;\nbtpConfig.requestTimeoutMs = 15_000; // optional; defaults to 10s and is capped at 60s\nconst subaccountDestinations = await listDestinationsAtLevel(btpConfig, 'subaccount', logger);\nconst { destination, authTokens } = await lookupDestinationWithUserToken(\n  btpConfig,\n  'MY_PP_DESTINATION',\n  authInfo.token,    // the verified bearer JWT (guarded: must be a 3-segment JWT, not an API key)\n  logger,\n);\n// authTokens: { sapConnectivityAuth?, bearerToken?, ppProxyAuth?, samlAssertionAuthorization? }\n\n// Drift-sensitive per-request lookup: bypasses both reads and writes of the SDK cache.\nawait lookupDestinationWithUserTokenUncached(btpConfig, 'MY_PP_DESTINATION', authInfo.token, logger);\n```\n\n**The package returns credentials + a proxy descriptor; it never applies them.** Your SAP HTTP client owns header assembly (`Authorization` / `SAP-Connectivity-Authentication` / `Proxy-Authorization`) and the forward-proxy request. What to do when no PP token is produced (throw vs. fall back to BasicAuth) is **your** policy.\n\nWhich `PerUserAuthTokens` field is populated depends on the destination's `Authentication` type (they're mutually exclusive). Apply whichever one is set:\n\n| `PerUserAuthTokens` field | Destination `Authentication` | Apply as |\n|---|---|---|\n| `sapConnectivityAuth` | `PrincipalPropagation` (Cloud Connector) | `SAP-Connectivity-Authentication` header, alongside `Proxy-Authorization` from the connectivity proxy |\n| `bearerToken` | `OAuth2UserTokenExchange` / `OAuth2SAMLBearerAssertion` | `Authorization: Bearer <bearerToken>` |\n| `samlAssertionAuthorization` | `SAMLAssertion` (e.g. S/4HANA Public Cloud developer extensibility — the same flow [SAP Business Application Studio](https://help.sap.com/docs/bas) uses) | `Authorization: <value>` **verbatim** (already prefixed, e.g. `SAML2.0 …`), alongside `x-sap-security-session: create` |\n| `ppProxyAuth` | — | Reserved (jwt-bearer \"Option 1\" → `Proxy-Authorization`); never produced by `lookupDestinationWithUserToken`, a consumer assigns it itself |\n\n| Export | Purpose |\n|--------|---------|\n| `parseVCAPServices(env?)` | Build a `BTPConfig` from `VCAP_SERVICES` (XSUAA + destination + connectivity bindings). |\n| `listDestinationsAtLevel(cfg, level, logger?)` | Fetch the complete `subaccount` or `instance` collection without the SDK cache. Basic credentials remain only in the explicit `User`/`Password` fields; `originalProperties` excludes known credential, token, authorization-header, and certificate material while preserving non-secret custom properties. |\n| `lookupDestination(cfg, name, logger?)` | Resolve a destination (works with BasicAuth destinations, no user JWT). |\n| `lookupDestinationWithUserToken(cfg, name, userJwt, logger?)` | The PP primitive — per-user destination + `PerUserAuthTokens`. JWT-only (anti-footgun). |\n| `lookupDestinationWithUserTokenUncached(cfg, name, userJwt, logger?)` | Same PP result with `useCache:false`; failed or successful resolutions cannot affect a later lookup. |\n| `createConnectivityProxy(cfg, locationId?, logger?)` | A `BTPProxyConfig` descriptor for the Cloud Connector connectivity proxy. |\n| `resolveBTPDestination(name, logger?)` | Convenience: destination → `{ url, username, password, client, proxy }`. |\n| `BTPRequestTimeoutError` | Typed timeout from direct BTP requests that are not intentionally wrapped in a more specific service error. Its `timeoutMs` field contains the effective bounded timeout. |\n| `DEFAULT_BTP_REQUEST_TIMEOUT_MS` / `MAX_BTP_REQUEST_TIMEOUT_MS` | Public 10-second default and 60-second hard cap for consumers that expose the setting. |\n\nDirect Destination and Connectivity Service requests use one abortable timeout for the fetch and response body together. Configure it with `BTPConfig.requestTimeoutMs`; invalid or non-positive values use the 10-second default, and values above 60 seconds are capped. This applies to service-token acquisition, collection/Find calls, Connectivity proxy tokens, and the direct principal-propagation fallback. The SAP Cloud SDK-owned per-user destination lookup manages its own transport and is not covered by this option.\n\n---\n\n## `@sap/xssec` is CommonJS — interop note\n\n`@sap/xssec` is **pure CommonJS** (no ESM entry). This package consumes it with a default import + destructure under `esModuleInterop`, which is the supported pattern from an ESM module on Node 22+:\n\n```ts\nimport xssec from '@sap/xssec';\nconst { XsuaaService, createSecurityContext } = xssec;   // NOT `import { XsuaaService } from '@sap/xssec'`\n```\n\nYou don't need to do this yourself — the package handles XSUAA validation internally. It's documented here because it's the one interop sharp edge if you extend the package or import `@sap/xssec` alongside it. A named ESM import (`import { XsuaaService } from '@sap/xssec'`) will fail.\n\n---\n\n## What's **not** included\n\nBy design, the package's job ends at producing `AuthInfo` + the raw bearer token (and, via `./btp`, destination credentials). These stay with the consuming server:\n\n- **Rate limiting** — per-IP and per-user limiters are deferred (see [`docs/SPEC.md §14`](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/SPEC.md)); each consumer keeps its own for now.\n- **Scope / tool policy** — `expandScopes` is an injected hook; the package owns no `ACTION_POLICY` or scope semantics.\n- **The MCP transport** — you own `/mcp` (stdio / Streamable HTTP); the package contributes middleware + the OAuth router.\n- **The SAP HTTP client** — header assembly, CSRF, cookies, stateful sessions, and the forward-proxy request are yours.\n- **Safety ceiling / server config / the MCP tools** — entirely consumer-owned.\n- **Helmet / CSP / HSTS** — broader HTTP hardening is yours (and must keep COOP unset for popup OAuth).\n\n---\n\n## Documentation\n\n- **[`docs/SPEC.md`](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/SPEC.md)** — the frozen API contract: every public signature, the dependency ranges, the logger contract, the auth↔PP coupling, and the adoption path for each consumer.\n- **[`docs/RESEARCH.md`](https://github.com/arc-mcp/xsuaa-auth/blob/main/docs/RESEARCH.md)** — extraction research, the three-way (arc-1 / calmcp / LISA) reality check, and the Architecture Decision Records.\n- **[`SECURITY.md`](./SECURITY.md)** — vulnerability reporting + the security-relevant configuration knobs.\n\n### A note on the logger\n\nThe injected `Logger` uses `(message, data?)` argument order:\n\n```ts\ninterface Logger {\n  debug(message: string, data?: Record<string, unknown>): void;\n  info(message: string, data?: Record<string, unknown>): void;\n  warn(message: string, data?: Record<string, unknown>): void;\n  error(message: string, data?: Record<string, unknown>): void;\n  emitAudit?(event: Record<string, unknown>): void;   // optional; always null-guarded\n}\n```\n\nIt's optional everywhere and defaults to a no-op (`noopLogger`). [pino](https://github.com/pinojs/pino) users (`(obj, msg)` order) pass a thin adapter:\n\n```ts\nconst adapter: Logger = {\n  debug: (m, d) => log.debug(d ?? {}, m),\n  info: (m, d) => log.info(d ?? {}, m),\n  warn: (m, d) => log.warn(d ?? {}, m),\n  error: (m, d) => log.error(d ?? {}, m),\n};\n```\n\n---\n\n## License\n\n[MIT](./LICENSE) © Marian Zeis\n","readmeFilename":"README.md"}