{"_id":"@brainwebuk/payload-plugin-mcp-oauth","_rev":"18-c3efde71d99b85f15b464b14bdc0ad48","name":"@brainwebuk/payload-plugin-mcp-oauth","dist-tags":{"latest":"0.5.0"},"versions":{"0.1.0":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.0","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.0","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"dist":{"shasum":"c590859d4f81970bcd27c210cf863f44e09a31ef","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.0.tgz","fileCount":15,"integrity":"sha512-Dy5mo0LTUU1aTvc7fri+pt0hCYvJgZwV2P3P6uz7lMPZWQjYzWq1hhga8KnQywjXoYRN+QZMkMnYRILoX0Un1Q==","signatures":[{"sig":"MEUCIQCFZMu979Qza1hcVgByeKCVV3KWwmVkhqzIcANUJQGf7gIgGbQ2zTXwGgseUGU1g3oQaVZHjTIu5+Hpy53z1aUFSRQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":374254},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"}},"gitHead":"da214f9187523576a371322329cfeb94cfbbba63","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ricbwood","email":"ric@brainweb.co.uk"},"_npmVersion":"11.8.0","directories":{},"_nodeVersion":"22.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"8.3.5","react":"19.2.6","vitest":"2.1.9","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.0_1780228922957_0.40285792915133745","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.1","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.1","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"dist":{"shasum":"a794bbdd37da6ba030d3f55dacbab48af6384dc8","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.1.tgz","fileCount":22,"integrity":"sha512-lcVbuxh9TG+OD9NfeLd9AoaELqroI//Wr9aJB8Ra3ESMRQ/G0/7r7skYQ9Ko6g5O1C6fG8dsf4n5VjgmMd0kxQ==","signatures":[{"sig":"MEUCIQDMIHYxfDFAfKqdRvyO7z+/XqkGUNhwyga0T1q5UvBpAAIgCCGssIn3E1kodD1Wo0Kak13Kd8hdMfIRzsQZSbzYrqY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":398233},"main":"./dist/index.cjs","type":"module","_from":"file:brainwebuk-payload-plugin-mcp-oauth-0.1.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ricbwood","email":"ric@brainweb.co.uk"},"_resolved":"/private/var/folders/mb/5dc_bhdj03b8jk8xy2x4m3m80000gp/T/848332fce6c0137b8894cb5089fbabc1/brainwebuk-payload-plugin-mcp-oauth-0.1.1.tgz","_integrity":"sha512-lcVbuxh9TG+OD9NfeLd9AoaELqroI//Wr9aJB8Ra3ESMRQ/G0/7r7skYQ9Ko6g5O1C6fG8dsf4n5VjgmMd0kxQ==","_npmVersion":"11.6.2","directories":{},"_nodeVersion":"25.2.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"2.1.9","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.1_1780483020364_0.7990284534669467","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.2","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.2","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"dist":{"shasum":"f083c57eb08126df73c088969543b4044ed54b26","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.2.tgz","fileCount":22,"integrity":"sha512-fXuNgPzi3j6U5+0Z0gsMVXFDLzB7TzPa9jPmqclkxbWnCz90eOCzMXyRno6ikcj3Rp6hHbJml+1RHSuIX246cA==","signatures":[{"sig":"MEYCIQDYMvDjEetRBAuMZOtNu01xJVBQxRMa/8M9kY22hJ5HKwIhAIe1+GgWQofOZwuAHfFA86uGnMtbHBGQj36UjwR9efs9","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":406042},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"76ca00b8b26c69bbbf25e823ca17fe69f632982e","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ricbwood","email":"ric@brainweb.co.uk"},"_npmVersion":"11.8.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"2.1.9","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.2_1780505759202_0.17241547801417445","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.3","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.3","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"dist":{"shasum":"bbe1ef581f3de135c57a1f3d4f8c1b628777adc9","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.3.tgz","fileCount":23,"integrity":"sha512-1k46E4B3O8sDl05pNqubNuHGFC03V4h1try038cIlB58jhCEMyMDu6pi8WpRYkHonBDdKyEHNiYrbnY6GnEfFA==","signatures":[{"sig":"MEUCIQCIQCnQ1l0d8ismXavsMz8nBa/1DUXasW9THHRhGVLIqwIgRE9L14UzyCW5k+A+oL82u+IgAktvEXjeyf4Rds9et+c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":417020},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"0bc172191953c180828826ed3f35182c35ba94f3","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"ricbwood","email":"ric@brainweb.co.uk"},"_npmVersion":"11.8.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"2.1.9","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.3_1780506814929_0.3416467084838757","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.4","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.4","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"f0b8279ed60a34309e2bf6d64cf28f24ee53bd5f","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.4.tgz","fileCount":23,"integrity":"sha512-EJphR0rFGa8tpF6+FAV1N/D6QdQhYLiuZn0dCEPXhVXzM20mcozsPGBOa3Nmc2AsRd4jEBsiy9Ykfqs2dhGNzw==","signatures":[{"sig":"MEYCIQDXknrAUZfEVgRSw7MChKxHmBlwLp1HYJYq4mCDoPm3dAIhAOiOxFN+kEV3IfNrWQZgekIUeuF8N3ypgPVAoIXpcabm","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":417327},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"953c03c1bdb446971a90bd7d43e885a16f6a2fc9","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"2.1.9","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.4_1780514926027_0.13398438670852508","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.5","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.5","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"19ff188459cb442e0b3c766a283cdd473363e51c","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.5.tgz","fileCount":25,"integrity":"sha512-lP+S91/N5bQyueNsRXQlOcqkaho3BN/y8pXb596DlgI4BvGlSbEejldeDvG1jR3Z3G+0JD7jbEfV5PcS0AMv/g==","signatures":[{"sig":"MEQCIEcEWuvIBENuCnltVW7kjFSR0uhIsPXxw5mpWM7I/a1HAiAyjCzqcid3oU5pmLKKRYapFu1jfWvlkMrsRChSWWAzTw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":423122},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"342f353568e3a68e3a5de5d783c2affaad1b1a2e","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.5_1780579816781_0.5334781001256745","host":"s3://npm-registry-packages-npm-production"}},"0.1.6":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.6","license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.6","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"d4b02bd1c4c63d72a97a15d4375b98e53587f8e3","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.6.tgz","fileCount":25,"integrity":"sha512-8d8nSZKj5gohmE43j1wQKUVOTWpdI2P7nbO5jZbj++FlmztxoBILO9KO9w1vmc8rZFQP+7HMyxtWhAklTaaBag==","signatures":[{"sig":"MEYCIQCi+uznk+sIG4Y6Qd4KgYszMVFm3Jh5aNB553kFwohfxAIhANnfpkg6SyPHSF+Zx6gsSZj8hXN7+aV9wxaofACOfTlB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.1.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":428760},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"c169f156fb64ef52813d40e90b638c8c08a58695","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.6_1780593513262_0.10397491125807057","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.1.7","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.1.7","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"2f18ba14849fe748816e653c3ba5f78acfb258aa","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.1.7.tgz","fileCount":25,"integrity":"sha512-2tS5MojWZ0Xmp4TnUVWgYfADL1R4dCOmT5u4/rGL+CqWOhBdRMNUZvpFtoLvtp/S7rnHNX4b1Kx32SptP1IhAA==","signatures":[{"sig":"MEUCIQD/v5UPM6M2lBPCa7Ia9vOBDlqXJR65CtsqgHo5V1hgLAIgKRlfl9lys0wsut7R9Qv4kPByJC0TXSOA/4JyWn2LFXk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.1.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":434097},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"3e2268b4afb01a3dddb8af1e9f355faa4525553d","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.1.7_1780596288400_0.4471193845021355","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.2.0","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.2.0","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"37f9cf8b90bcda5208efbf4bd59fa2fbc1fc56d5","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.2.0.tgz","fileCount":25,"integrity":"sha512-IaX9xE/hWB2sYn8t+bizuJMTD1J8LbL6hep9CXhOCoVHQq64O1QvWTUpgfp1/tzd+t9v3q/vGC9ZgKhyd6Lvlw==","signatures":[{"sig":"MEUCIHiZXVNeZgSkz61Fw7SStp9QgCJA0N/ovpk46FigtQp3AiEAkP8E6dOOKiT9na4y9P+cfDNn5yFDFpTtY5Jp1cSfKo8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":499975},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"fe4499714cb94c703bd96afde58377a44342edde","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.2.0_1780653331770_0.2034040488330784","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.0","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.0","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"a8d5328b259b091af919cd9df83b7bf87a84566b","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.0.tgz","fileCount":25,"integrity":"sha512-l4TGaX54FWBLDEZMEjaxCze6Ufe7pYYSwtCKEZ/SD94K52iRFxkNyOfUWenz2lClwwfKvaUIDnRCq46x55AGFQ==","signatures":[{"sig":"MEYCIQC524177JzwfRetYFXxG5oaUFwv2U04qvzrhLXK7aP7xQIhAKF362zUW5T7KyOmw/ox4IfeaoGUa/HKJvAIuyp21WVh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":513635},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"bbf013f4f3fa02e7516673f6b6eded44261b190f","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.0_1780679982245_0.6510794510296802","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.1","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.1","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"f937a1cf9f8d88c3627252b4e4a92a3732e7fe37","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.1.tgz","fileCount":25,"integrity":"sha512-pw9Gt4KJNeZIiMvPc43zJpe9AwG3bA/n+yocCyOF38cddHdRHE8Tn7uBMfyiWBYNphfmIqKXN+ZkX4KjLSpjXQ==","signatures":[{"sig":"MEUCIQCH7H7hNpUn6dM9hu0yX59pSD99N+1L2MxV/32tq+3bZQIgD+Vy2RNPq3fnd4SFtuAQCxRHl9CWfCONfJWsJmQd0cs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":517248},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"1bd4dadbaeb9948079921e6094688bd5f05a753d","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.1_1780689231622_0.4286043627010645","host":"s3://npm-registry-packages-npm-production"}},"0.3.2":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.2","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.2","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"87e4dc39fb4bd9264743385d8204c255f3ea7357","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.2.tgz","fileCount":25,"integrity":"sha512-vkYc0r8vr8RZAKCxBM7JWynnLfDNwqZ8RQT5nS5UabpyJ+/+DK9Zs633aorN8dlbmU3LFzw9t5nuzuUxlJvzGg==","signatures":[{"sig":"MEYCIQDwTMJPJvFZ0MCr5unjghsAmn64gJi6PszS1vcIkTGn8gIhAKnrP/YkbGfHFyaOBGoKguNymiKh5jSDAp00KBsBjqEw","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":523570},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"faebd1acbc6d20485072083794c4c06725ce5bcc","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.2_1780740149916_0.19320013629314703","host":"s3://npm-registry-packages-npm-production"}},"0.3.3":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.3","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.3","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/ricbwood/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/ricbwood/payload-mcp-oauth/issues"},"dist":{"shasum":"6dbfefd11d5e29c0bb121f78b87855a75632c7f9","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.3.tgz","fileCount":25,"integrity":"sha512-MtkW79u1fu9Ktnngf6LDRMaelLoPc4UU0Q6j6JT5OH38KPBk2REVzLs5dYhe7xOGzqPX2V2c0PeaSTM5ayLroA==","signatures":[{"sig":"MEUCIQCfIXvCTfk9mjesiSpzEu8TFyMC82laj+uMpx9+g4UA+wIgTDU/6y+yPAE4al+6FIfV+hw0a0Czldnu4lqHNs11I+Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":533429},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"a148f0dcb0dfd959aafeca9ead7c4e769ad964a9","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:1814c195-e8ae-4242-a30e-71733166a165"}},"repository":{"url":"git+https://github.com/ricbwood/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.3_1780743750412_0.05208705791495927","host":"s3://npm-registry-packages-npm-production"}},"0.3.4":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.4","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.4","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"dist":{"shasum":"944a569447bd575ffec9e46d6f05833092acd35a","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.4.tgz","fileCount":25,"integrity":"sha512-Aq7uWLugSUMmQFgft1ZhIhk3FRz1CoZ0go6N4WJmytdA61It0IfdIohnOhCdFDuXBioXyx9p4o2fmaCfgMD0yg==","signatures":[{"sig":"MEUCIQCj22NAUPE0LyPF+MRGk4rXdzTW/4LrIHdfnOk5n24UpQIgZo0CBWOXuKVmwgLSLqRATFVDc1ponilhaeilitthekM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":536134},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"72c0f1900798242fe293932afb871fb74527eb37","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e03282d-19b6-4fb5-af4a-eeca9049bf67"}},"repository":{"url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.16.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.4_1780918923800_0.7104961140405097","host":"s3://npm-registry-packages-npm-production"}},"0.3.5":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.5","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.5","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"dist":{"shasum":"d54868623e8c62d3265707788c4f379ee435baef","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.5.tgz","fileCount":25,"integrity":"sha512-ywXvYh+mB+oq73spi/bTINq8RbeHHLqPl7xWejTCUQbK7VocerrJRjjhB3JeT+rzVwgRHb20kpJwgeKssuDkOg==","signatures":[{"sig":"MEQCIEqWdmfymghZztnpX0qWg8ouGlD0GnqsrNRprLjU/z6gAiB6w0TA7YikTjUFigEcdL2Hdk6WBdHJD14UFuR9UVH+Xg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":536134},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"2883a52d0559769f5b03fde517186bbd4bde0e6d","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e03282d-19b6-4fb5-af4a-eeca9049bf67"}},"repository":{"url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.17.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.5_1781554563277_0.819206455609808","host":"s3://npm-registry-packages-npm-production"}},"0.3.6":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.3.6","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.3.6","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"dist":{"shasum":"7077b1bc0d0bc1f5560c013f1d85fc5d74658572","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.3.6.tgz","fileCount":25,"integrity":"sha512-AKzhr7/q5UvICQSe8p16U4sOmASMWOhFgQNkKqb3QiT+qQfYWaNT7671XngIK9kEGqidxCEfKLkLwPfCjwMyzQ==","signatures":[{"sig":"MEUCIQDleYkX1wv2advVkDhJkfAYBx12V9G0JM4nlcYQB8w5WAIgJ/XPYCsR/TAvKEGHM0uj4kfP1e+b8N+DmvQ144g785Y=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.3.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":536134},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"461cd474ba7a5285b543164a29ad44405b86458c","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e03282d-19b6-4fb5-af4a-eeca9049bf67"}},"repository":{"url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"11.17.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.6","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.3.6_1782215175510_0.6907461070687797","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.4.0","author":{"url":"https://www.brainweb.co.uk/","name":"Richard Wood","email":"ric@brainweb.co.uk"},"license":"MIT","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.4.0","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"dist":{"shasum":"81d4de29b016ad3bba69830a3e2701dfbe5efa9b","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.4.0.tgz","fileCount":27,"integrity":"sha512-LTtyMQX4yuHB6swJfDZcDqYDcncCMqIrMfRj+LHHCiIkkAYtUjWYCZiRqz6NTAP6cxbilkHzz3jcaSYvnmDZoQ==","signatures":[{"sig":"MEQCIGWKDUv9AY5slUioistWhSoFGmL0EyrfXRStxOZV4OyIAiABvkz5zVxP0qpudBbQtqRWujkgCFeAUXN/cD6hxkVW7A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":562314},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"gitHead":"086edf1758efca97d490ef5bf0256b78028e17bb","scripts":{"lint":"eslint src","test":"vitest run --passWithNoTests","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e03282d-19b6-4fb5-af4a-eeca9049bf67"}},"repository":{"url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","type":"git","directory":"packages/plugin"},"_npmVersion":"12.0.2","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.2.11","tsup":"8.3.5","react":"19.2.6","vitest":"4.1.8","payload":"3.85.0","react-dom":"19.2.6","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","@payloadcms/plugin-mcp":"3.85.0"},"peerDependencies":{"next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","payload":"^3.0.0","react-dom":"^18.0.0 || ^19.0.0","@payloadcms/plugin-mcp":"^3.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/payload-plugin-mcp-oauth_0.4.0_1787651214769_0.6933210902603777","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@brainwebuk/payload-plugin-mcp-oauth","version":"0.5.0","license":"MIT","author":{"name":"Richard Wood","email":"ric@brainweb.co.uk","url":"https://www.brainweb.co.uk/"},"repository":{"type":"git","url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","directory":"packages/plugin"},"homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","require":"./dist/index.cjs"},"./admin":{"types":"./dist/admin/index.d.ts","import":"./dist/admin/index.js","require":"./dist/admin/index.cjs"},"./middleware":{"types":"./dist/next-middleware.d.ts","import":"./dist/next-middleware.js","require":"./dist/next-middleware.cjs"}},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","lint":"eslint src","test":"vitest run --passWithNoTests"},"peerDependencies":{"payload":"^3.0.0","@payloadcms/plugin-mcp":"^3.0.0","next":"^14.0.0 || ^15.0.0 || ^16.0.0","react":"^18.0.0 || ^19.0.0","react-dom":"^18.0.0 || ^19.0.0"},"peerDependenciesMeta":{"next":{"optional":true}},"devDependencies":{"payload":"3.85.0","@payloadcms/plugin-mcp":"3.85.0","@types/react":"^19.0.0","@types/react-dom":"^19.0.0","next":"16.2.11","react":"19.2.6","react-dom":"19.2.6","tsup":"8.3.5","vitest":"4.1.8"},"publishConfig":{"access":"public"},"gitHead":"94b86608a95b12ae4a1ab1ff5a490824c3d7b4d2","_id":"@brainwebuk/payload-plugin-mcp-oauth@0.5.0","description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","_nodeVersion":"22.23.2","_npmVersion":"12.0.2","dist":{"integrity":"sha512-aP6iZ6ZM+K9QK9eVomTmBR+FqRnoX3lx4et3jsdLBUsbkmltqgPAC+RCcXniigAVThXmHr7H09wvIYy8yGpqrA==","shasum":"508de24397aae7a38b2736aae37e2b7a16129074","tarball":"https://registry.npmjs.org/@brainwebuk/payload-plugin-mcp-oauth/-/payload-plugin-mcp-oauth-0.5.0.tgz","fileCount":27,"unpackedSize":631618,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brainwebuk%2fpayload-plugin-mcp-oauth@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGUwGxapBNZygxhmmjmE475uL2SVl70ZHbAbuHiW29ECAiAl7skXaJ3Kqhl4S9vLitRWY9dJCx35Amd870qbKm/XOA=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:9e03282d-19b6-4fb5-af4a-eeca9049bf67"}},"directories":{},"maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/payload-plugin-mcp-oauth_0.5.0_1788349422491_0.5478909741802624"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-31T12:02:02.777Z","modified":"2026-09-02T11:43:42.950Z","0.1.0":"2026-05-31T12:02:03.109Z","0.1.1":"2026-06-03T10:37:00.513Z","0.1.2":"2026-06-03T16:55:59.349Z","0.1.3":"2026-06-03T17:13:35.136Z","0.1.4":"2026-06-03T19:28:46.192Z","0.1.5":"2026-06-04T13:30:16.959Z","0.1.6":"2026-06-04T17:18:33.407Z","0.1.7":"2026-06-04T18:04:48.550Z","0.2.0":"2026-06-05T09:55:31.934Z","0.3.0":"2026-06-05T17:19:42.423Z","0.3.1":"2026-06-05T19:53:51.767Z","0.3.2":"2026-06-06T10:02:30.056Z","0.3.3":"2026-06-06T11:02:30.578Z","0.3.4":"2026-06-08T11:42:03.945Z","0.3.5":"2026-06-15T20:16:03.426Z","0.3.6":"2026-06-23T11:46:15.666Z","0.4.0":"2026-08-25T09:46:54.908Z","0.5.0":"2026-09-02T11:43:42.631Z"},"bugs":{"url":"https://github.com/BrainWeb/payload-mcp-oauth/issues"},"author":{"name":"Richard Wood","email":"ric@brainweb.co.uk","url":"https://www.brainweb.co.uk/"},"license":"MIT","homepage":"https://github.com/BrainWeb/payload-mcp-oauth/tree/main/packages/plugin#readme","repository":{"type":"git","url":"git+https://github.com/BrainWeb/payload-mcp-oauth.git","directory":"packages/plugin"},"description":"OAuth 2.1 + PKCE + Dynamic Client Registration for [`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp), so a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai** alongside the existing API-key flow.","maintainers":[{"name":"ricbwood","email":"ric@brainweb.co.uk"}],"readme":"# @brainwebuk/payload-plugin-mcp-oauth\n\nOAuth 2.1 + PKCE + Dynamic Client Registration for\n[`@payloadcms/plugin-mcp`](https://www.npmjs.com/package/@payloadcms/plugin-mcp),\nso a Payload-backed MCP server can be added as a **Custom Connector in Claude.ai**\nalongside the existing API-key flow.\n\nThe plugin is **purely additive**: it wraps the MCP endpoint handler and adds the\nOAuth endpoints and collections. Your existing API-key MCP clients keep working\nunchanged.\n\n- OAuth 2.1 authorization-code flow with **PKCE (S256 only)**\n- **Dynamic Client Registration** (RFC 7591) — Claude.ai self-registers\n- Discovery via RFC 8414 / RFC 9728 well-known documents\n- Tokens hashed at rest (HMAC-SHA-256); refresh + revocation supported\n- **OAuth Clients** and **OAuth Tokens** appear as admin collections under the\n  **MCP** nav group (admin-only; the public REST/GraphQL surface stays closed)\n\n> **Installing with an AI coding agent?** Point it at\n> [`INSTALL_FOR_AGENTS.md`](./INSTALL_FOR_AGENTS.md) (shipped in this\n> npm package) — a step-by-step playbook with per-step verification and the\n> failure modes to watch for. Or just follow the manual steps below.\n\n---\n\n## Requirements\n\n| | Version |\n|---|---|\n| `payload` | `^3.0.0` |\n| `@payloadcms/plugin-mcp` | `^3.0.0` (tested 3.85.0) |\n| `next` | `^14 \\|\\| ^15 \\|\\| ^16` (only for the exported proxy/middleware) |\n| Node | `>= 20` |\n\n---\n\n## Install\n\n### 1. Add the package\n\n```bash\npnpm add @brainwebuk/payload-plugin-mcp-oauth\n# or: npm i / yarn add\n```\n\n### 2. Register the plugin (after `mcpPlugin`)\n\nIn `payload.config.ts`, register `payloadMcpOAuth()` **immediately after**\n`mcpPlugin()`, and pass it the **same** options object you gave to `mcpPlugin()`.\n\n```ts\nimport { mcpPlugin } from '@payloadcms/plugin-mcp'\nimport type { MCPPluginConfig } from '@payloadcms/plugin-mcp'\nimport { payloadMcpOAuth } from '@brainwebuk/payload-plugin-mcp-oauth'\nimport { buildConfig } from 'payload'\n\n// Assign ONCE to a const and reuse the same reference in both calls. ⚠️\nconst mcpOptions: MCPPluginConfig = {\n  collections: {\n    users: { enabled: { find: true, update: true } },\n    media: { enabled: { find: true, create: true } },\n  },\n}\n\nexport default buildConfig({\n  // ...db, collections, admin, etc.\n  plugins: [\n    mcpPlugin(mcpOptions),\n    payloadMcpOAuth({\n      issuer: process.env.NEXT_PUBLIC_SERVER_URL || 'http://localhost:3000',\n      mcpPluginOptions: mcpOptions, // ← the SAME object, not a copy\n    }),\n  ],\n})\n```\n\n> ⚠️ **Pass the same object reference to both calls.** The plugin installs its\n> token-validation hook by mutating `mcpOptions`. If you pass a fresh object or a\n> spread/copy to either call, OAuth tokens will silently fail to authenticate\n> (the API-key path keeps working, which makes this easy to miss). The plugin\n> also throws on boot if it is registered *before* `mcpPlugin()`.\n\n> **Design note — why we mutate `mcpPluginOptions`.** Payload's plugin guidance\n> says \"never mutate the incoming config,\" and everything this plugin *adds*\n> (collections, endpoints) is done by spreading the incoming config, not mutating\n> it. The one deliberate exception is `mcpPluginOptions`: the OAuth token\n> validator has to live inside `@payloadcms/plugin-mcp`'s request-handler closure,\n> which Payload captures when *that* plugin runs — so we must set `overrideAuth` on\n> the shared options object *before* `mcpPlugin()` executes (hence the\n> same-reference rule above). This mutates a **sibling plugin's** options, which the\n> [Plugin API](https://payloadcms.com/docs/plugins/plugin-api) explicitly permits\n> (`plugins['…']?.options`), rather than our own incoming config. It's the most\n> fragile part of the setup, so we're tracking less-footgun-prone alternatives in\n> [issue #51](https://github.com/BrainWeb/payload-mcp-oauth/issues/51).\n\n### 3. Add the proxy (Next.js 16) / middleware (Next.js 14–15)\n\nOAuth discovery (`/.well-known/...`) and bare-host MCP connectors need two\nhost-level URL rewrites that a Payload plugin cannot register on its own. The\nplugin ships them as a ready-made request handler — wire it up with the file\nconvention your Next.js version uses (next to your `app/` directory). Re-export\nthe handler, but declare `config` as a **local** literal.\n\n**Next.js 16+** — Next renamed the `middleware` convention to `proxy`. Create\n`src/proxy.ts`:\n\n```ts\nexport { mcpOAuthMiddleware as proxy } from '@brainwebuk/payload-plugin-mcp-oauth/middleware'\n\nexport const config = {\n  matcher: [\n    '/',\n    '/.well-known/oauth-authorization-server',\n    '/.well-known/oauth-protected-resource',\n  ],\n}\n```\n\n**Next.js 14–15** — the `proxy` convention doesn't exist yet; create\n`src/middleware.ts` with the same body, exported as `middleware`:\n\n```ts\nexport { mcpOAuthMiddleware as middleware } from '@brainwebuk/payload-plugin-mcp-oauth/middleware'\n\nexport const config = {\n  matcher: [\n    '/',\n    '/.well-known/oauth-authorization-server',\n    '/.well-known/oauth-protected-resource',\n  ],\n}\n```\n\n> ⚠️ **Don't re-export `config`** (e.g. `export { ..., config } from '…/middleware'`).\n> Next.js parses the matcher at compile time and, as of **Next 16**, hard-errors\n> with *\"can't recognize the exported `config` field … it mustn't be reexported\"*\n> — which 500s **every** route in your app. The matcher must be a static literal\n> in your `proxy.ts` / `middleware.ts` itself.\n>\n> On Next 16 a `middleware.ts` still works but logs a deprecation warning — prefer\n> `proxy.ts`. Migrate an existing file with `npx @next/codemod middleware-to-proxy .`.\n\nAlready have a proxy/middleware? Compose it instead (shown for Next 16; on 14–15\nname the file `middleware.ts` and the function `middleware`):\n\n```ts\nimport type { NextRequest } from 'next/server'\nimport { createMcpOAuthMiddleware } from '@brainwebuk/payload-plugin-mcp-oauth/middleware'\n\nconst mcpOAuth = createMcpOAuthMiddleware() // accepts { apiRoute, mcpEndpointPath, ... }\n\nexport function proxy(request: NextRequest) {\n  // ...your logic first...\n  return mcpOAuth(request)\n}\n\nexport const config = {\n  matcher: ['/', '/.well-known/oauth-authorization-server', '/.well-known/oauth-protected-resource' /* + yours */],\n}\n```\n\n> No `next.config.ts` rewrites are required — the proxy/middleware handles discovery.\n\n### 4. Set environment variables\n\n```bash\n# Public HTTPS URL clients reach. Used as the OAuth issuer + in discovery metadata.\nNEXT_PUBLIC_SERVER_URL=https://cms.example.com\n\n# HMAC pepper for hashing tokens at rest — REQUIRED in production (>= 32 chars).\n# Generate with: openssl rand -hex 32\nPMOAUTH_TOKEN_PEPPER=<64-hex-chars>\n```\n\nIn development a built-in insecure pepper is used if `PMOAUTH_TOKEN_PEPPER` is\nunset (with a warning). In `NODE_ENV=production` the plugin **throws on boot** if\nit is missing or shorter than 32 characters.\n\n> **Set `PMOAUTH_TOKEN_PEPPER` locally too.** `next build` and `next start` set\n> `NODE_ENV=production` whether or not you are deploying, so a local production\n> build hits the same boot check. Put the pepper in your local `.env` and\n> `pnpm build` works on your machine.\n>\n> A `http://localhost` (or `127.0.0.1` / `[::1]`) issuer is *exempt* from the\n> HTTPS requirement for exactly this reason — a loopback URL is not reachable off\n> your machine, so there is no transport to protect. Any other host still has to\n> be `https://` under `NODE_ENV=production`.\n\n> **Keep `serverURL` consistent.** The authorize/consent flow signs the user in\n> with a first-party Payload **session cookie**, so Payload's `serverURL` must be\n> the same public origin clients reach (the same value as `NEXT_PUBLIC_SERVER_URL`).\n> Most starters already do this via `getServerSideURL()`. If `serverURL` doesn't\n> match the origin the browser actually uses, the consent **Approve** POST can\n> lose its session — see Troubleshooting.\n\n### 5. Regenerate the admin import map (if your app uses one)\n\nThis plugin registers no custom admin components, so it doesn't *require* an import\nmap regeneration. If your app already maintains `src/app/(payload)/admin/importMap.js`,\nregenerating it after installing is harmless and keeps it tidy:\n\n```bash\npnpm payload generate:importmap\n```\n\n(Drop the `src/` prefix if your app doesn't use a `src` directory.)\n\n### 6. Apply the schema change\n\nThe plugin adds collections (`oauth-clients`, `oauth-auth-codes`, `oauth-tokens`,\n`oauth-csrf-nonces`). Use whichever schema workflow your app already uses — **don't\nmix them**:\n\n- **Dev push** (default for SQLite/Postgres in dev): just start the app; the new\n  tables are pushed on next boot. Do **not** run `migrate:create`/`migrate` against\n  a push-synced dev DB — you'll get *\"table … already exists\"*.\n- **Migrations** (production): run `pnpm payload migrate:create` to generate a\n  migration that includes the new collections, then `pnpm payload migrate`.\n\nThat's it — start the app and the OAuth endpoints are live, with **OAuth Clients**\nand **OAuth Tokens** under the **MCP** group in the admin sidebar.\n\n---\n\n## Connect from Claude.ai\n\n1. Settings → **Connectors** → **Add custom connector**.\n2. Enter your server URL (the bare host, e.g. `https://cms.example.com`, works —\n   the middleware routes it to the MCP endpoint).\n3. Claude.ai discovers the auth server, dynamically registers, and starts the\n   OAuth + PKCE handshake.\n4. You'll be sent to your Payload admin login + a consent screen; approve to\n   issue a token.\n\nVerify discovery is reachable:\n\n```bash\ncurl https://cms.example.com/.well-known/oauth-protected-resource\ncurl https://cms.example.com/.well-known/oauth-authorization-server\n```\n\n---\n\n## Making the MCP usable for AI agents\n\nOnce connected, an agent only knows what the MCP server *tells* it. Tools\ngenerated from rich collections (a page builder with nested blocks, conditional\nfields, etc.) are large and non-obvious, so agents trial-and-error their way\nthrough `create*` calls. Close that gap with the guidance channels\n`@payloadcms/plugin-mcp` exposes — all delivered **server → agent** over the\nprotocol, so they reach every client (Claude.ai web, Desktop, Code, and\nnon-Claude MCP clients):\n\n- **`serverOptions.instructions`** — a \"how to use this server\" string on `mcpPlugin()`.\n- **per-collection `description`** — tells the agent when/why to use a collection.\n- **field `admin.description`** — flows into each tool's input schema, so the\n  agent reads field rules inline (e.g. \"required only when …\").\n- **`prompts`** — pre-baked, guided workflows the agent can invoke.\n\n```ts\nmcpPlugin({\n  serverOptions: {\n    serverInfo: { name: 'Author Website', version: '1.0.0' },\n    instructions: `\nThis server manages an author marketing site (pages, posts, media).\n- Publish by setting \"_status\": \"published\".\n- pages.hero.type is none|lowImpact|mediumImpact|highImpact; high/mediumImpact\n  REQUIRE hero.media (a Media id) — upload first; prefer lowImpact otherwise.\n- pages.layout is an array of blocks: content, cta, mediaBlock, archive, formBlock.\n- If a tool schema is large, create a minimal doc first, then add blocks with the update tool.`,\n  },\n  collections: {\n    pages: {\n      description: 'Landing/marketing pages built from a hero + layout blocks.',\n      enabled: { find: true, create: true, update: true },\n    },\n  },\n})\n```\n\n> **Why not ship a Claude Skill for this?** Skills load only from the *consuming*\n> client's own environment — an MCP server (or this npm package) cannot push a\n> Skill to a connecting Claude.ai/Desktop agent. `instructions`/`prompts` are the\n> protocol-native equivalent and reach every client automatically. (A Skill *is*\n> useful for the **install** experience — see below.)\n\n### Install helper for Claude Code (optional)\n\nThe [project repo](https://github.com/BrainWeb/payload-mcp-oauth) doubles as a\nClaude Code plugin marketplace with an `install` skill that walks Claude Code\nthrough wiring up the plugin (config, proxy, env, schema) and the common\npitfalls. In Claude Code:\n\n```\n/plugin marketplace add BrainWeb/payload-mcp-oauth\n/plugin install payload-mcp-oauth@brainwebuk\n```\n\nThen ask Claude Code to \"install payload-plugin-mcp-oauth\" (or run\n`/payload-mcp-oauth:install`). This helps the **developer** installing the plugin;\nbecause Skills are client-side it has no effect on the runtime connector agent.\n\n---\n\n## Configuration\n\n| Option | Type | Default | Description |\n|---|---|---|---|\n| `issuer` | `string` | — (required) | Public base URL; OAuth issuer + metadata base. |\n| `mcpPluginOptions` | `MCPPluginConfig` | — (required) | The **same** object passed to `mcpPlugin()`. |\n| `userCollection` | `string` | `'users'` | Collection holding user accounts. |\n| `disabled` | `boolean` | `false` | Turn OAuth off without uninstalling: no endpoints, no token wiring, `mcpPluginOptions` untouched (API-key MCP keeps working). Collections stay registered for schema consistency. Also auto-detected when `mcpPluginOptions.disabled` is set. |\n| `adminAccess` | `Access` | member of `userCollection` who passes the role check | Who may view/manage the OAuth collections in the admin. Honours a `role`/`isAdmin`/`roles` field when your collection has one. See below. |\n| `loginPath` | `string` | `routes.admin` + `admin.routes.login` | Where to send an unauthenticated user to sign in. Derived from your Payload config, so a custom admin or login route is picked up automatically. Set it only if sign-in lives outside the admin panel. |\n| `accessTokenTtlSeconds` | `number` | `3600` | Access-token lifetime. |\n| `refreshTokenTtlSeconds` | `number` | `86400` | Refresh-token lifetime. |\n| `authCodeTtlSeconds` | `number` | `300` | Authorization-code lifetime. |\n| `rateLimits` | `RateLimitOptions` | `{}` | Per-endpoint rate-limit overrides. Per-process and in-memory — see the caveat below. |\n\n### Scopes\n\nA client may request a narrowed grant with a space-separated `scope`, where each\ntoken is `<collection-or-global-slug>:<operation>`:\n\n| Scope token | Grants (collections) | Grants (globals) |\n|---|---|---|\n| `<slug>:read` | `find` | `find` |\n| `<slug>:write` | `create` + `update` | `update` |\n| `<slug>:delete` | `delete` | — (rejected) |\n\n```\nscope=posts:read posts:write media:read\n```\n\n**Requesting no scope grants everything the operator has enabled** — RFC 6749\n§3.3's pre-defined default, and what Claude.ai's Custom Connector does. The\nconsent screen says which of the two is happening.\n\nScope can only ever *narrow*:\n\n- Every operation a token names must be enabled on the server, or the whole\n  request is rejected with `invalid_scope` — there are no partial grants. A\n  collection with only `find` enabled offers `:read` and refuses `:write`.\n- The scope is validated at `/authorize`, re-validated at `/consent` (so\n  tampering with the hidden form field is caught), and resolved again when the\n  code is redeemed.\n- Grants are resolved against your **live** config on every request, not frozen\n  at consent. A **scoped** grant names a fixed set, so it can only shrink —\n  disabling an operation removes it from existing tokens on their next call. A\n  **no-scope** grant means \"whatever is enabled now\", so it tracks the config in\n  both directions: enable a new collection and an already-connected client picks\n  it up, with no re-authorisation.\n\nThe exact set your server accepts is published in\n`/.well-known/oauth-authorization-server` as `scopes_supported`, derived from\nyour `mcpPluginOptions` — so you never have to maintain the list by hand.\n\n### Rate limits\n\nThe built-in limiters are a speed bump against casual abuse, not a security\ncontrol — PKCE, the single-use CSRF nonce and the session gate are what protect\nthe flow. Two caveats worth knowing before you rely on them:\n\n- **Buckets are keyed on `x-forwarded-for`,** which is client-supplied unless\n  something upstream overwrites it. Behind a proxy or load balancer that sets the\n  header itself, the limits hold; exposed directly to the internet, a caller can\n  rotate the header for a fresh quota per request.\n- **Buckets live in one process's memory.** Across several instances the\n  effective ceiling is your configured limit times the instance count, and on\n  serverless every cold start begins with empty buckets.\n\nIf you need limits that actually bind, put them in front of the app — at your\nproxy, CDN or WAF.\n\n### Admin UI & access\n\n`oauth-clients` and `oauth-tokens` render as collections under the **MCP** nav\ngroup (alongside the MCP plugin's API Keys). `read`/`update`/`delete` are gated by\n`adminAccess`; `create` is always denied (clients self-register via DCR, tokens are\nminted by the token endpoint). `oauth-auth-codes` and `oauth-csrf-nonces` stay\nhidden and fully locked.\n\nThe default `adminAccess` denies the public REST/GraphQL surface and authorises an\nauthenticated user who is **in your `userCollection`** *and* passes an admin\ncheck that honours whichever role field your collection has:\n\n| Your user collection has | Default rule authorises |\n|---|---|\n| a `role` field | `role === 'admin'` |\n| an `isAdmin` field | `isAdmin === true` |\n| a `roles` array | `roles` includes `'admin'` |\n| none of the above | any member of the collection |\n\nSo the standard Payload starters (no role field) are unaffected, while apps that\nalready carry roles get the tighter gate automatically.\n\n⚠️ **If your operators carry a role other than `admin`** — `editor`, `owner`,\n`staff` — this default locks them out of the OAuth screens. Pass your own rule.\n\n⚠️ **If your `userCollection` mixes admins with untrusted end-users** and has no\nrole field, the default reduces to \"any logged-in user\", who could then rewrite a\nclient's `redirectUris` (→ auth-code theft) or revoke others' tokens. Pass your\nown rule:\n\n```ts\npayloadMcpOAuth({\n  issuer,\n  mcpPluginOptions: mcpOptions,\n  adminAccess: ({ req }) => req.user?.role === 'admin',\n})\n```\n\n### Endpoints added\n\n`GET /.well-known/oauth-authorization-server`, `GET /.well-known/oauth-protected-resource`,\n`POST /api/oauth/register`, `GET /api/oauth/authorize`, `POST /api/oauth/consent`,\n`POST /api/oauth/token`, `POST /api/oauth/revoke`.\n\nOAuth tokens use the `pmoauth_` prefix. The MCP handler checks the Bearer value:\n`pmoauth_…` takes the OAuth path; anything else delegates to the original API-key\nhandler unchanged.\n\n---\n\n## Troubleshooting\n\n| Symptom | Likely cause |\n|---|---|\n| `Error: payloadMcpOAuth must be registered AFTER mcpPlugin()` | Plugin order — put `payloadMcpOAuth()` after `mcpPlugin()`. |\n| `Error: payloadMcpOAuth: mcpPluginOptions is not the same object you passed to mcpPlugin()` | Exactly what it says — you passed a spread or a fresh literal to one of them (step 2). Assign the options to a `const` and pass that same `const` to both. |\n| OAuth tokens 401 but API keys work | `mcpPluginOptions` wasn't the **same** object reference (step 2). Since 0.5.0 this is caught at boot with the error above instead of failing silently — if you see the 401 without that error, check `PMOAUTH_TOKEN_PEPPER` matches the one the tokens were issued under. |\n| `/.well-known/...` returns the app's HTML / 404 | `proxy.ts` / `middleware.ts` missing or its `matcher` doesn't include the well-known paths (step 3). |\n| **Every** route 500s; log says *\"can't recognize the exported `config` field … it mustn't be reexported\"* | `config` was re-exported from `…/middleware` instead of declared as a local literal in your `proxy.ts` / `middleware.ts` (step 3). |\n| `The \"middleware\" file convention is deprecated` warning (Next 16) | Rename `src/middleware.ts` → `src/proxy.ts` and export the handler as `proxy` (step 3). |\n| Consent screen renders, but **Approve** returns `401 access_denied / \"Authentication required\"` | Plugin bug in **≤ 0.3.0**: the consent page sent `Referrer-Policy: no-referrer`, so browsers sent `Origin: null` on the Approve POST and Payload dropped the session (the `GET` render has no `Origin`, so it worked; the `POST` didn't). **Fixed in 0.3.1 — upgrade.** If it persists on ≥ 0.3.1, your `serverURL` doesn't match the origin the browser uses — check `NEXT_PUBLIC_SERVER_URL` (exact scheme + host, no trailing slash). |\n| **OAuth Clients / OAuth Tokens** missing from the admin nav, or their route shows *\"Nothing found\"* | The logged-in user isn't authorised by `adminAccess`. By default they must belong to `userCollection`; for mixed-role apps pass a custom `adminAccess` (see *Admin UI & access*). |\n| `migrate` fails with *\"table … already exists\"* | You ran `migrate` against a DB already created by dev push — pick one workflow (step 6). |\n| `SQLITE_ERROR: no such column: oauth_clients_id` while rebuilding `payload_locked_documents_rels` on `pnpm dev` | SQLite push can't add the new collections' lock-FK columns to an **already-pushed** DB (a Payload/drizzle rebuild quirk). **Fixed in 0.3.2** — the OAuth collections set `lockDocuments: false`, so they add no column there. On ≤ 0.3.1: add the plugin *before* first boot, or reset the dev DB (`rm your.db*`) so the schema is created fresh. |\n| Boots fine in dev, throws on deploy | `PMOAUTH_TOKEN_PEPPER` not set in production (step 4). |\n\n---\n\n## License\n\nMIT\n","readmeFilename":"README.md"}