{"_id":"@asgardeo/mcp-express","_rev":"5-b1fe3cfac1cf98e0e5ff7b4c7385a742","name":"@asgardeo/mcp-express","dist-tags":{"latest":"0.3.0"},"versions":{"0.0.1":{"name":"@asgardeo/mcp-express","version":"0.0.1","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"author":{"name":"WSO2"},"license":"Apache-2.0","_id":"@asgardeo/mcp-express@0.0.1","maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"homepage":"https://github.com/asgardeo/mcp-express/tree/main/packages/mcp-express#readme","bugs":{"url":"https://github.com/asgardeo/mcp-express/issues"},"dist":{"shasum":"0256e1dd25c104e127edb27aa7c5cce58726d3dc","tarball":"https://registry.npmjs.org/@asgardeo/mcp-express/-/mcp-express-0.0.1.tgz","fileCount":20,"integrity":"sha512-5WoJ3lh+weCWats6HbJ+DY4CF9yEM1W3Tvvtpi1QBDBOuNizA0IT7CkVzMIWxroFeYv1BxnXGjIoW/yUkBQ1sQ==","signatures":[{"sig":"MEQCIHQ6FgzckuFZDUZxm2IQIBus4RdeWHzD38JYE5a3M03oAiAadGx3GTHwPtKXoUMmLb7WtMP9THN2OtFMtjJcdRM4wQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57978},"main":"dist/cjs/index.js","type":"module","_from":"file:asgardeo-mcp-express-0.0.1.tgz","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18.0.0"},"exports":{"import":"./dist/index.js","require":"./dist/cjs/index.js"},"scripts":{"lint":"eslint --ext .ts,.js src","build":"node ./scripts/build.js","clean":"rm -rf dist","fix:lint":"eslint --fix --ext .ts,.js src","build:cjs":"esbuild src/index.ts --bundle --platform=node --outfile=dist/cjs/index.js --format=cjs --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:esm":"esbuild src/index.ts --bundle --platform=node --outfile=dist/index.js --format=esm --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:types":"tsc --emitDeclarationOnly --declaration"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"_resolved":"/tmp/f8e151192a302fba4a90a444bc447353/asgardeo-mcp-express-0.0.1.tgz","_integrity":"sha512-5WoJ3lh+weCWats6HbJ+DY4CF9yEM1W3Tvvtpi1QBDBOuNizA0IT7CkVzMIWxroFeYv1BxnXGjIoW/yUkBQ1sQ==","repository":{"url":"git+https://github.com/asgardeo/mcp-express.git","type":"git","directory":"packages/mcp-express"},"_npmVersion":"10.9.2","description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","directories":{},"_nodeVersion":"22.15.0","dependencies":{"cors":"^2.8.5","tslib":"^2.8.1","express":"^4.21.2","@asgardeo/mcp-node":"^0.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","esbuild":"^0.25.4","prettier":"^2.6.2","typescript":"~5.7.2","@types/cors":"^2.8.17","@types/node":"^22.15.3","@types/express":"^4.17.21","@wso2/eslint-plugin":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/eslint-plugin?4ee6f6be232d7631999d709a86b91612f1d34ce7","@wso2/prettier-config":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/prettier-config?4ee6f6be232d7631999d709a86b91612f1d34ce7"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/mcp-express_0.0.1_1747665863856_0.17466999631752045","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@asgardeo/mcp-express","version":"0.1.0","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"author":{"name":"WSO2"},"license":"Apache-2.0","_id":"@asgardeo/mcp-express@0.1.0","maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"homepage":"https://github.com/asgardeo/mcp-express/tree/main/packages/mcp-express#readme","bugs":{"url":"https://github.com/asgardeo/mcp-express/issues"},"dist":{"shasum":"126721f667dfd6d6c0f65c5b771f7ca7bbcdd4de","tarball":"https://registry.npmjs.org/@asgardeo/mcp-express/-/mcp-express-0.1.0.tgz","fileCount":22,"integrity":"sha512-4kNeOCEZJhy7lWzhn/OLMsA7Hu6v1snW+kxHSiW/t6GBO2mdGyCcX3N8Vr7oEJadqxyo92j1sAoQu7aW6rE/AA==","signatures":[{"sig":"MEYCIQClnodNlALEJWTWoM0hBT7J5aWR/7LbEi8+cgmgn1MnFwIhAKMDCdWsXqaEDXtepACoomqIeEPQ6z63xNzUIxMvi6LX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":65907},"main":"dist/cjs/index.js","type":"module","_from":"file:asgardeo-mcp-express-0.1.0.tgz","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18.0.0"},"exports":{"import":"./dist/index.js","require":"./dist/cjs/index.js"},"scripts":{"lint":"eslint --ext .ts,.js src","build":"node ./scripts/build.js","clean":"rm -rf dist","fix:lint":"eslint --fix --ext .ts,.js src","build:cjs":"esbuild src/index.ts --bundle --platform=node --outfile=dist/cjs/index.js --format=cjs --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:esm":"esbuild src/index.ts --bundle --platform=node --outfile=dist/index.js --format=esm --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:types":"tsc --emitDeclarationOnly --declaration"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"_resolved":"/tmp/fff5c6f00d84151f9d6f892bcd83fda9/asgardeo-mcp-express-0.1.0.tgz","_integrity":"sha512-4kNeOCEZJhy7lWzhn/OLMsA7Hu6v1snW+kxHSiW/t6GBO2mdGyCcX3N8Vr7oEJadqxyo92j1sAoQu7aW6rE/AA==","repository":{"url":"git+https://github.com/asgardeo/mcp-express.git","type":"git","directory":"packages/mcp-express"},"_npmVersion":"10.9.2","description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","directories":{},"_nodeVersion":"22.15.0","dependencies":{"cors":"^2.8.5","tslib":"^2.8.1","express":"^4.21.2","@asgardeo/mcp-node":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","esbuild":"^0.25.4","prettier":"^2.6.2","typescript":"~5.7.2","@types/cors":"^2.8.17","@types/node":"^22.15.3","@types/express":"^4.17.21","@wso2/eslint-plugin":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/eslint-plugin?4ee6f6be232d7631999d709a86b91612f1d34ce7","@wso2/prettier-config":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/prettier-config?4ee6f6be232d7631999d709a86b91612f1d34ce7"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/mcp-express_0.1.0_1747829741154_0.7124732015760817","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@asgardeo/mcp-express","version":"0.2.0","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"author":{"name":"WSO2"},"license":"Apache-2.0","_id":"@asgardeo/mcp-express@0.2.0","maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"homepage":"https://github.com/asgardeo/mcp-express/tree/main/packages/mcp-express#readme","bugs":{"url":"https://github.com/asgardeo/mcp-express/issues"},"dist":{"shasum":"edf1a0e1389b262752b808936f7de62256151cc1","tarball":"https://registry.npmjs.org/@asgardeo/mcp-express/-/mcp-express-0.2.0.tgz","fileCount":22,"integrity":"sha512-pDGYuhFM0ZlB9we0xoYe0TRNfEXIxibuuzAVb62+BkDUmg+JSrB1zlIlj2kt/OIztpSjegpqhgQFJenNK8jAgg==","signatures":[{"sig":"MEQCIEbcyL/I1OpYIzMPMwTh1fyZWmIFfWgGmvEa4zgj2z0hAiA0tjnKDX2LeSewF+2QyvBSZjaQXLis2DSN7kbdDq7+tw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68056},"main":"dist/cjs/index.js","type":"module","_from":"file:asgardeo-mcp-express-0.2.0.tgz","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18.0.0"},"exports":{"import":"./dist/index.js","require":"./dist/cjs/index.js"},"scripts":{"lint":"eslint --ext .ts,.js src","build":"node ./scripts/build.js","clean":"rm -rf dist","fix:lint":"eslint --fix --ext .ts,.js src","build:cjs":"esbuild src/index.ts --bundle --platform=node --outfile=dist/cjs/index.js --format=cjs --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:esm":"esbuild src/index.ts --bundle --platform=node --outfile=dist/index.js --format=esm --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:types":"tsc --emitDeclarationOnly --declaration"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"_resolved":"/tmp/d3497684c3955c145eae88d04bea0ec0/asgardeo-mcp-express-0.2.0.tgz","_integrity":"sha512-pDGYuhFM0ZlB9we0xoYe0TRNfEXIxibuuzAVb62+BkDUmg+JSrB1zlIlj2kt/OIztpSjegpqhgQFJenNK8jAgg==","repository":{"url":"git+https://github.com/asgardeo/mcp-express.git","type":"git","directory":"packages/mcp-express"},"_npmVersion":"10.9.3","description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","directories":{},"_nodeVersion":"22.18.0","dependencies":{"cors":"^2.8.5","tslib":"^2.8.1","express":"^4.21.2","@asgardeo/mcp-node":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","esbuild":"^0.25.4","prettier":"^2.6.2","typescript":"~5.7.2","@types/cors":"^2.8.17","@types/node":"^22.15.3","@types/express":"^4.17.21","@wso2/eslint-plugin":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/eslint-plugin?4ee6f6be232d7631999d709a86b91612f1d34ce7","@wso2/prettier-config":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/prettier-config?4ee6f6be232d7631999d709a86b91612f1d34ce7"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/mcp-express_0.2.0_1755074869939_0.8738448598263922","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@asgardeo/mcp-express","version":"0.2.1","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"author":{"name":"WSO2"},"license":"Apache-2.0","_id":"@asgardeo/mcp-express@0.2.1","maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"homepage":"https://github.com/asgardeo/mcp-auth-javascript/tree/main/packages/mcp-express#readme","bugs":{"url":"https://github.com/asgardeo/mcp-auth-javascript/issues"},"dist":{"shasum":"cf0fed77028a6cd24e4a668d1892ecc4460502f3","tarball":"https://registry.npmjs.org/@asgardeo/mcp-express/-/mcp-express-0.2.1.tgz","fileCount":22,"integrity":"sha512-jn0Gv5AWpXDY5WHv81cMaf2ivcrC+jhvo/eKlkNSzNdRjo6SFaiQjOiijWog0immWNv11ljFqW+XuCDdm3dRvQ==","signatures":[{"sig":"MEUCIGa4j7Vj906VWnQpNTkpgv11Ng3+yyNyzDEKelMcBZ3FAiEAkgoM38fp3vxmLeP0M3JGSjqonK6O2cp2IfRljLXNbdI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68300},"main":"dist/cjs/index.js","type":"module","_from":"file:asgardeo-mcp-express-0.2.1.tgz","types":"dist/index.d.ts","module":"dist/index.js","engines":{"node":">=18.0.0"},"exports":{"import":"./dist/index.js","require":"./dist/cjs/index.js"},"scripts":{"lint":"eslint --ext .ts,.js src","build":"node ./scripts/build.js","clean":"rm -rf dist","fix:lint":"eslint --fix --ext .ts,.js src","build:cjs":"esbuild src/index.ts --bundle --platform=node --outfile=dist/cjs/index.js --format=cjs --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:esm":"esbuild src/index.ts --bundle --platform=node --outfile=dist/index.js --format=esm --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:types":"tsc --emitDeclarationOnly --declaration"},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"_resolved":"/tmp/8e468e3b24849091e48c4265939edea8/asgardeo-mcp-express-0.2.1.tgz","_integrity":"sha512-jn0Gv5AWpXDY5WHv81cMaf2ivcrC+jhvo/eKlkNSzNdRjo6SFaiQjOiijWog0immWNv11ljFqW+XuCDdm3dRvQ==","repository":{"url":"git+https://github.com/asgardeo/mcp-auth-javascript.git","type":"git","directory":"packages/mcp-express"},"_npmVersion":"10.9.3","description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","directories":{},"_nodeVersion":"22.20.0","dependencies":{"cors":"^2.8.5","tslib":"^2.8.1","express":"^4.21.2","@asgardeo/mcp-node":"^0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","esbuild":"^0.25.4","prettier":"^2.6.2","typescript":"~5.7.2","@types/cors":"^2.8.17","@types/node":"^22.15.3","@types/express":"^4.17.21","@wso2/eslint-plugin":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/eslint-plugin?4ee6f6be232d7631999d709a86b91612f1d34ce7","@wso2/prettier-config":"https://gitpkg.now.sh/brionmario/wso2-ui-configs/packages/prettier-config?4ee6f6be232d7631999d709a86b91612f1d34ce7"},"peerDependencies":{"express":">=4"},"_npmOperationalInternal":{"tmp":"tmp/mcp-express_0.2.1_1761033050331_0.99842412047048","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@asgardeo/mcp-express","version":"0.3.0","description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"homepage":"https://github.com/asgardeo/mcp-auth-javascript/tree/main/packages/mcp-express#readme","bugs":{"url":"https://github.com/asgardeo/mcp-auth-javascript/issues"},"author":{"name":"WSO2"},"license":"Apache-2.0","type":"module","main":"dist/cjs/index.js","module":"dist/index.js","exports":{"import":"./dist/index.js","require":"./dist/cjs/index.js"},"types":"dist/index.d.ts","repository":{"type":"git","url":"git+https://github.com/asgardeo/mcp-auth-javascript.git","directory":"packages/mcp-express"},"devDependencies":{"@types/cors":"^2.8.17","@types/express":"^4.17.21","@types/node":"^22.15.3","@wso2/eslint-plugin":"git+https://github.com/brionmario/wso2-ui-configs.git#d3041825a4f8f235c8f9fa36b55cf29d54e791c8&path:packages/eslint-plugin","@wso2/prettier-config":"git+https://github.com/brionmario/wso2-ui-configs.git#d3041825a4f8f235c8f9fa36b55cf29d54e791c8&path:packages/prettier-config","esbuild":"^0.25.4","eslint":"8.57.0","prettier":"^2.6.2","typescript":"~5.7.2"},"peerDependencies":{"express":">=4"},"publishConfig":{"access":"public"},"dependencies":{"cors":"^2.8.5","express":"^4.21.2","tslib":"^2.8.1","@asgardeo/mcp-node":"^0.3.0"},"engines":{"node":">=18.0.0"},"scripts":{"clean":"rm -rf dist","build":"node ./scripts/build.js","build:types":"tsc --emitDeclarationOnly --declaration","build:esm":"esbuild src/index.ts --bundle --platform=node --outfile=dist/index.js --format=esm --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","build:cjs":"esbuild src/index.ts --bundle --platform=node --outfile=dist/cjs/index.js --format=cjs --sourcemap --minify --external:express --external:cors --external:@asgardeo/mcp-node","fix:lint":"eslint --fix --ext .ts,.js src","lint":"eslint --ext .ts,.js src"},"_id":"@asgardeo/mcp-express@0.3.0","_integrity":"sha512-whGUiA81L8mEmbzu+qSsmiROBxEqllGrLxeb6RqkFi6Y5kU7XTsxEkNaIrhZt7Mr3E9fn+5eVJqkyaNkbZ09zw==","_resolved":"/tmp/2a2b5d89ec93e2fe8edfe47486ca185e/asgardeo-mcp-express-0.3.0.tgz","_from":"file:asgardeo-mcp-express-0.3.0.tgz","_nodeVersion":"24.14.0","_npmVersion":"11.9.0","dist":{"integrity":"sha512-whGUiA81L8mEmbzu+qSsmiROBxEqllGrLxeb6RqkFi6Y5kU7XTsxEkNaIrhZt7Mr3E9fn+5eVJqkyaNkbZ09zw==","shasum":"7400987572ac43824a1f5fe7c13b85e89b68fb3f","tarball":"https://registry.npmjs.org/@asgardeo/mcp-express/-/mcp-express-0.3.0.tgz","fileCount":24,"unpackedSize":73224,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICz6F72B4Du5ncCk2XmG96/OwFOpMrTc7eBqHG0AauZhAiB4ZUM38Av1gDTXrqWJiH5mBCkYamvnX87+BoNNACYGJQ=="}]},"_npmUser":{"name":"wso2-org","email":"techops@wso2.com"},"directories":{},"maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-express_0.3.0_1773937607076_0.7176278596610823"},"_hasShrinkwrap":false}},"time":{"created":"2025-05-19T14:44:23.790Z","modified":"2026-03-19T16:26:47.343Z","0.0.1":"2025-05-19T14:44:24.085Z","0.1.0":"2025-05-21T12:15:41.427Z","0.2.0":"2025-08-13T08:47:50.119Z","0.2.1":"2025-10-21T07:50:50.534Z","0.3.0":"2026-03-19T16:26:47.215Z"},"bugs":{"url":"https://github.com/asgardeo/mcp-auth-javascript/issues"},"author":{"name":"WSO2"},"license":"Apache-2.0","homepage":"https://github.com/asgardeo/mcp-auth-javascript/tree/main/packages/mcp-express#readme","keywords":["asgardeo","agents","mcp","mcp-express","mcp-auth","authorization"],"repository":{"type":"git","url":"git+https://github.com/asgardeo/mcp-auth-javascript.git","directory":"packages/mcp-express"},"description":"Express middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.","maintainers":[{"name":"wso2-org","email":"techops@wso2.com"}],"readme":"# @asgardeo/mcp-express\n\n[![npm version](https://img.shields.io/npm/v/@asgardeo/mcp-express.svg?style=flat-square)](https://www.npmjs.com/package/@asgardeo/mcp-express)\n[![npm downloads](https://img.shields.io/npm/dm/@asgardeo/mcp-express.svg?style=flat-square)](https://www.npmjs.com/package/@asgardeo/mcp-express)\n\nExpress middleware for enforcing Model Context Protocol (MCP) authorization using Asgardeo.\n\n## Overview\n\nThis package provides Express middleware that implements Model Context Protocol (MCP) based authorization for Express.js\napplications. It integrates with Asgardeo for authentication and authorization services.\n\nThis package is part of the [Asgardeo MCP Node.js SDKs monorepo](https://github.com/asgardeo/asgardeo-mcp-node#readme).\nFor overall project information, contribution guidelines, and details on other related packages, please refer to the\nmain repository.\n\n## Installation\n\n```bash\nnpm install @asgardeo/mcp-express\n# or\nyarn add @asgardeo/mcp-express\n# or\npnpm add @asgardeo/mcp-express\n```\n\n## Features\n\n- Easy-to-use Express middleware\n- Protected route handling\n- Automatic metadata endpoint setup\n- Built-in CORS support\n- Seamless integration with Asgardeo\n\n## Usage\n\n### Basic Setup\n\n```typescript\nimport express from 'express';\nimport {McpAuthServer} from '@asgardeo/mcp-express';\n\nconst app = express();\n\n// Initialize McpAuthServer\nconst mcpAuthServer = new McpAuthServer({\n  baseUrl: process.env.AUTH_SERVER_BASE_URL as string,\n  issuer: process.env.ISSUER as string,\n  resource: 'http://localhost:8000/mcp', // MCP server URL\n});\n\napp.use(express.json());\napp.use(mcpAuthServer.router());\n\n// Protect your MCP endpoint\napp.post('/mcp', mcpAuthServer.protect(), async (req, res) => {\n  // Your MCP handling logic here\n});\n```\n\n### API Reference\n\n#### McpAuthServer(options)\n\nCreates a new instance of the MCP authentication server with the given configuration.\n\n```typescript\nimport {McpAuthServer} from '@asgardeo/mcp-express';\n\nconst mcpAuthServer = new McpAuthServer({\n  baseUrl: 'https://auth.example.com'\n  issuer: 'https://auth.example.com/oauth2/token'\n  resource: 'http://localhost:8000/mcp'\n});\n```\n\nIf you are using Asgardeo this will be\n\n```typescript\nimport {McpAuthServer} from '@asgardeo/mcp-express';\n\nconst mcpAuthServer = new McpAuthServer({baseUrl: 'https://api.asgardeo.io/t/<your-organization>'});\n```\n\n#### mcpAuthServer.router()\n\nReturns an Express router that sets up the necessary endpoints for MCP authentication.\n\n```typescript\napp.use(mcpAuthServer.router());\n```\n\n#### mcpAuthServer.protect()\n\nReturns middleware that protects routes requiring authentication. This middleware should be applied before your route\nhandler.\n\n```typescript\napp.post('/api/protected', mcpAuthServer.protect(), async (req, res) => {\n  // Your protected route logic here\n});\n```\n\n### Configuration\n\nThe server can be configured with the following option:\n\n```typescript\ninterface McpAuthServerOptions {\n  /** Base URL of the authorization server */\n  baseUrl: string;\n}\n```\n\n## Example\n\nHere's a complete example of setting up an Express server with MCP authentication:\n\n```typescript\nimport {randomUUID} from 'node:crypto';\nimport {McpAuthServer} from '@asgardeo/mcp-express';\nimport {McpServer} from '@modelcontextprotocol/sdk/server/mcp';\nimport {StreamableHTTPServerTransport} from '@modelcontextprotocol/sdk/server/streamableHttp';\nimport {isInitializeRequest} from '@modelcontextprotocol/sdk/types';\nimport {config} from 'dotenv';\nimport express, {Express, Request, Response} from 'express';\nimport {z} from 'zod';\n\nconfig();\n\nconst app: Express = express();\n\n// Initialize McpAuthServer\nconst mcpAuthServer = new McpAuthServer({\n  baseUrl: process.env.BASE_URL as string,\n});\n\napp.use(express.json());\napp.use(mcpAuthServer.router());\n\n// Session management\ninterface TransportMap {\n  [sessionId: string]: {\n    lastAccess: number;\n    transport: StreamableHTTPServerTransport;\n  };\n}\n\nconst transports: TransportMap = {};\nconst SESSION_TIMEOUT_MS: number = 30 * 60 * 1000;\n\nconst isSessionExpired = (lastAccessTime: number): boolean => Date.now() - lastAccessTime > SESSION_TIMEOUT_MS;\n\n// MCP endpoint with authentication\napp.post(\n  '/mcp',\n  mcpAuthServer.protect(),\n  async (req: Request, res: Response): Promise<void> => {\n    try {\n      const sessionId: string | undefined = req.headers['mcp-session-id'] as string | undefined;\n      let transport: StreamableHTTPServerTransport;\n\n      // Handle existing session or create new one\n      if (sessionId && transports[sessionId]) {\n        // Session management code...\n        transport = transports[sessionId].transport;\n        transports[sessionId].lastAccess = Date.now();\n      } else if (!sessionId && isInitializeRequest(req.body)) {\n        // Extract bearer token if present\n        let bearerToken: string | undefined;\n        const authHeader: string | undefined = req.headers.authorization as string | undefined;\n        if (authHeader && authHeader.toLowerCase().startsWith('bearer ')) {\n          bearerToken = authHeader.substring(7);\n          console.log(`Bearer token captured for new session.`);\n        }\n\n        // Create MCP server and configure tools\n        transport = new StreamableHTTPServerTransport({\n          // Transport configuration...\n        });\n\n        const server: McpServer = new McpServer({\n          name: 'example-server',\n          version: '1.0.0',\n        });\n\n        // Define MCP tools\n        server.tool(\n          'get_pet_vaccination_info',\n          'Retrieves the vaccination history for a specific pet.',\n          {\n            petId: z.string().describe('The unique identifier for the pet.'),\n          },\n          async ({petId}) => {\n            // Tool implementation using bearer token\n            return {\n              content: [\n                {\n                  text: `Retrieved vaccination info for pet ID: ${petId}. Token was ${\n                    bearerToken ? 'present' : 'absent'\n                  }.`,\n                  type: 'text',\n                },\n              ],\n            };\n          },\n        );\n\n        await server.connect(transport);\n      } else {\n        // Handle invalid requests\n        res.status(400).json({\n          error: {\n            code: -32000,\n            message: 'Bad Request',\n          },\n          id: req.body?.id || null,\n          jsonrpc: '2.0',\n        });\n        return;\n      }\n\n      await transport.handleRequest(req, res, req.body);\n    } catch (error) {\n      // Error handling\n    }\n  }),\n);\n\nconst PORT: string | number = process.env.PORT || 3000;\napp.listen(PORT, (): void => {\n  console.log(`MCP server running on port ${PORT}`);\n});\n```\n\n### Prerequisites\n\n- Node.js 16.x or later\n- pnpm 8.x or later\n\n### Setup\n\n1. Clone the repository\n2. Install dependencies:\n\n```bash\npnpm install\n```\n\n### Build\n\n```bash\npnpm build\n```\n\n### Lint\n\n```bash\npnpm lint\n```\n\n## License\n\nApache-2.0 - see the [LICENSE](LICENSE) file for details.\n","readmeFilename":"README.md"}