{"_id":"mcp-auth","_rev":"12-b7cdd92c5fbce476100f597a54a5e0d9","name":"mcp-auth","dist-tags":{"latest":"1.0.0-beta.1"},"versions":{"0.0.0":{"name":"mcp-auth","version":"0.0.0","keywords":[],"author":"","license":"ISC","_id":"mcp-auth@0.0.0","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"dist":{"shasum":"3d22d85b03cc20be6f16a6d86d2e26ad5331c93d","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.0.0.tgz","fileCount":1,"integrity":"sha512-looRkRYlwPJUdz3yvn2Cj4acsXov91TwIYh93o3Gki6jK3EPrOb/R0xHlUBAAd1Rs7Pz+kCtlogAT1tk6ySGOA==","signatures":[{"sig":"MEUCICnFmF7+grNXlKSS17UnbYzh08/i7RgiMt1CT7LPebhbAiEAqteE2ry31o2Eeeb6k45UifXZZwMjiVVJ9icyFUb75gc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":270},"main":"index.js","_from":"file:mcp-auth-0.0.0.tgz","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"_resolved":"/private/var/folders/lq/7sljkztx0rv36dtjbms9c64r0000gn/T/fbe2068cc2cf69825e6b43f6c23561e8/mcp-auth-0.0.0.tgz","_integrity":"sha512-looRkRYlwPJUdz3yvn2Cj4acsXov91TwIYh93o3Gki6jK3EPrOb/R0xHlUBAAd1Rs7Pz+kCtlogAT1tk6ySGOA==","_npmVersion":"10.9.2","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.0.0_1743641830115_0.5266653422636427","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-beta.0":{"name":"mcp-auth","version":"0.1.0-beta.0","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.0-beta.0","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"c14f373e00a3b2c01631f52a436dfbcda68cecda","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.0-beta.0.tgz","fileCount":22,"integrity":"sha512-i2RE+m0rA3IeU5Qka0LO7F+ab4zZHhY0ENmk1RNRekMMI4HOIkuge4a4Nbw20784jbEP64RU+kyenMms0aJ5PA==","signatures":[{"sig":"MEUCIF++Z/CUzVW2RLAtw22UBtFgeyxFu9cUMsPOVTtyJmryAiEAlnexIapiyLMs+GRjlfCQoldLbXp6teoiA/mnd3WNmSs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.0-beta.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":71867},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.0-beta.0.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/d43a0ca89d82f6ed71eb2ace66f697d4/mcp-auth-0.1.0-beta.0.tgz","_integrity":"sha512-i2RE+m0rA3IeU5Qka0LO7F+ab4zZHhY0ENmk1RNRekMMI4HOIkuge4a4Nbw20784jbEP64RU+kyenMms0aJ5PA==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Connect your MCP server to any eligible OAuth 2 or OpenID Connect provider","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.0-beta.0_1746464039500_0.2720245376542654","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-beta.1":{"name":"mcp-auth","version":"0.1.0-beta.1","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.0-beta.1","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"f4d42135e7645a33077119c8876ede1ec371ad19","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.0-beta.1.tgz","fileCount":23,"integrity":"sha512-3WKqrGolTQict/FzA/dJgGVnM8asyysvdJEutIKpoc38tc9lKikZofETGEuoR1weYnyvHLHZGth2lcTsx34fww==","signatures":[{"sig":"MEYCIQDtZsOytn0PqTS3iHZThuu1ABFzNmk9BD7FuKm9dssArAIhAIXIXk1dw86iXjNsy1mAkFzOroeBlzaUjgR2MEUSzc7F","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.0-beta.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":73043},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.0-beta.1.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/51928bab89aafb3cfaf751d7fd4731f6/mcp-auth-0.1.0-beta.1.tgz","_integrity":"sha512-3WKqrGolTQict/FzA/dJgGVnM8asyysvdJEutIKpoc38tc9lKikZofETGEuoR1weYnyvHLHZGth2lcTsx34fww==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.0-beta.1_1746464747143_0.37416904118193983","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-beta.2":{"name":"mcp-auth","version":"0.1.0-beta.2","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.0-beta.2","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"2d374b4eab8aaa7eb94746f76d17350c5de5f53f","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.0-beta.2.tgz","fileCount":23,"integrity":"sha512-P2mT5mI0nRFraYR9IUVlMPRmg3EKes17GLjROseo3fCUlDh+8DdLiLEixAiHYmfHnsfmD7NuDrK+X4rlEhIsIA==","signatures":[{"sig":"MEYCIQCGEiza4sGU0nVHs+GZXFNgfF6FM+XAyB7CE1M1E1AyOwIhAOPgwVG9v31LzgKA6Hs9eUTqB93Tog4vx8hqMlTemPLn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.0-beta.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":75856},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.0-beta.2.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/25c5a0a9fffa3d5fde4186e04f380189/mcp-auth-0.1.0-beta.2.tgz","_integrity":"sha512-P2mT5mI0nRFraYR9IUVlMPRmg3EKes17GLjROseo3fCUlDh+8DdLiLEixAiHYmfHnsfmD7NuDrK+X4rlEhIsIA==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.0-beta.2_1746470139003_0.961985183617029","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-beta.3":{"name":"mcp-auth","version":"0.1.0-beta.3","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.0-beta.3","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"3e2b4230c40289d8a279a85d7b672171be4bdf38","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.0-beta.3.tgz","fileCount":23,"integrity":"sha512-GrOm+TCZhdV2Q4+r64SRxMGfIplLF55MzRJfn22gmc3+ndXGtj7+w+rKQcFID5vJHxXXZR29ZV3ByG5IXVH86w==","signatures":[{"sig":"MEUCIAXUv6AJmTiB3Vy0v1piS2/JhFrS4v+/DgpqBV/q9ZQKAiEAwQPUfvTJjtrP02AAKNE4SnnkV4eags6sGSkUtLCkQLQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.0-beta.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":76007},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.0-beta.3.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"./*":{"import":"./lib/*","svelte":"./lib/*","default":"./lib/*","require":"./lib/*"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/31a9cc47cd67066d1d4611fa76a1323e/mcp-auth-0.1.0-beta.3.tgz","_integrity":"sha512-GrOm+TCZhdV2Q4+r64SRxMGfIplLF55MzRJfn22gmc3+ndXGtj7+w+rKQcFID5vJHxXXZR29ZV3ByG5IXVH86w==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.0-beta.3_1746472066300_0.23152024950265426","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"mcp-auth","version":"0.1.0","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.0","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"cc3b58dd82276ad84dbf3009fabbe648c77ed538","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.0.tgz","fileCount":23,"integrity":"sha512-Tc7w5ByaQnOFDk0zkXbr7BZh81+PtoLkB/LdohN/Ip+RbdSbHrVQNdm5YHDde0qmkxsEbI6yrWGh07PsiGo48g==","signatures":[{"sig":"MEYCIQC8ivH+tGcfidWJVOMmsS2oqsFbsRvtBGT9WcNjrqv6qgIhAPw8hh8FTOH3vJYA57YUEC+0QOkcbv18OqKUZRiYgf0X","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":75642},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.0.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"./*":{"import":"./lib/*","svelte":"./lib/*","default":"./lib/*","require":"./lib/*"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/e220f4df1da14eb5fe5e705e8638291c/mcp-auth-0.1.0.tgz","_integrity":"sha512-Tc7w5ByaQnOFDk0zkXbr7BZh81+PtoLkB/LdohN/Ip+RbdSbHrVQNdm5YHDde0qmkxsEbI6yrWGh07PsiGo48g==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.0_1746765176440_0.5809732186243415","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"mcp-auth","version":"0.1.1","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.1.1","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"1dc137f3307ad3153d5efa099fcedc241f11ce24","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.1.1.tgz","fileCount":23,"integrity":"sha512-cigQCJMbe32S6YbAqwKx53Oq22G78DmHJu5HZH8gR2eSbvvnJmHrfw7ucNZ5WKgO4Hw5L3afQWPMCiTqIndUWQ==","signatures":[{"sig":"MEUCIQCWpJdi586alnDnAWidw/vCQ3ieUcPpwVIqra6H629mXwIgNBroDJ1VcCPj9OkOTQrfXricb3tADGFyg5Es2bDuTNY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":76128},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.1.1.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0"},"exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"./*":{"import":"./lib/*","svelte":"./lib/*","default":"./lib/*","require":"./lib/*"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/e68ac87766ccda9d09ee7d4aa653f936/mcp-auth-0.1.1.tgz","_integrity":"sha512-cigQCJMbe32S6YbAqwKx53Oq22G78DmHJu5HZH8gR2eSbvvnJmHrfw7ucNZ5WKgO4Hw5L3afQWPMCiTqIndUWQ==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.2","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.15.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.11.0","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.1.1_1747871568731_0.8899995601841793","host":"s3://npm-registry-packages-npm-production"}},"0.2.0-beta.1":{"name":"mcp-auth","version":"0.2.0-beta.1","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.2.0-beta.1","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"735ccb1078a9d0ecc851fb135860469813a8bb22","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.2.0-beta.1.tgz","fileCount":43,"integrity":"sha512-SzpjuKIcr5W4WWZgemIXEwCq0glxDM5qqlgGtuo9xf94XtpOwgmd1KlBcRfwhoD8EtUwXH9u7hKLfvKx8gqwTw==","signatures":[{"sig":"MEQCIG4Ps4VpsGYNqFRRcl+a+Yqp6gBtqc681cO/CAKyxmugAiBYx/8Lzx+87q1UL12RCOjOBquNdlbCkmgxFD89h9Q2VQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.2.0-beta.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":126385},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.2.0-beta.1.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0 || ^24.0.0"},"exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"./*":{"import":"./lib/*","svelte":"./lib/*","default":"./lib/*","require":"./lib/*"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/7e9cc2b3e90f5c545dc63ab6a8c7154f/mcp-auth-0.2.0-beta.1.tgz","_integrity":"sha512-SzpjuKIcr5W4WWZgemIXEwCq0glxDM5qqlgGtuo9xf94XtpOwgmd1KlBcRfwhoD8EtUwXH9u7hKLfvKx8gqwTw==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.3","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.18.0","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.17.1","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.2.0-beta.1_1754888616517_0.8337504653723153","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"mcp-auth","version":"0.2.0","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","_id":"mcp-auth@0.2.0","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"}],"homepage":"https://github.com/mcp-auth/js#readme","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"dist":{"shasum":"c9f1f11cdf4d0c515e85b4f31a75d492cbfd448a","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-0.2.0.tgz","fileCount":45,"integrity":"sha512-k+OhvwdNzrZz01cvtuRiAv3yvd4oDQAUTfAlYnHlO8LTeHxoKOA5nDqtpXmtmWBp1F+NhtXGGzWxQvzpwTAjQA==","signatures":[{"sig":"MEUCIHDnUn1ljUr9CWts5UfgqpgAx7wqLlZPrfk2fsGr0TSrAiEAgydttlvPIdDyNeneLFKgGxTjYKF7fXK4j4uY/If70rk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":139644},"main":"./lib/index.js","type":"module","_from":"file:mcp-auth-0.2.0.tgz","types":"./lib/index.d.ts","module":"./lib/index.js","engines":{"node":"^20.19.0 || ^22.0.0 || ^23.0.0 || ^24.0.0"},"exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","svelte":"./lib/index.js","default":"./lib/index.js","require":"./lib/index.js"},"./*":{"import":"./lib/*","svelte":"./lib/*","default":"./lib/*","require":"./lib/*"}},"scripts":{"dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","lint":"eslint src","test":"vitest","build":"rm -rf lib/ && tsc -p tsconfig.build.json"},"_npmUser":{"name":"gaosun","email":"gao.npm@gmail.com"},"prettier":"@silverhand/eslint-config/.prettierrc","_resolved":"/tmp/970ec647a079762279fd01e550ebafe0/mcp-auth-0.2.0.tgz","_integrity":"sha512-k+OhvwdNzrZz01cvtuRiAv3yvd4oDQAUTfAlYnHlO8LTeHxoKOA5nDqtpXmtmWBp1F+NhtXGGzWxQvzpwTAjQA==","repository":{"url":"git+https://github.com/mcp-auth/js.git","type":"git","directory":"packages/mcp-auth"},"_npmVersion":"10.9.4","description":"Plug and play auth for Model Context Protocol (MCP) servers","directories":{},"_nodeVersion":"22.21.1","dependencies":{"zod":"^3.24.3","cors":"^2.8.5","jose":"^6.0.10","camelcase-keys":"^9.1.3","snakecase-keys":"^8.0.1","@silverhand/essentials":"^2.9.2"},"eslintConfig":{"extends":"@silverhand"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"nock":"^14.0.4","eslint":"^8.57.0","vitest":"^3.1.1","express":"5.0.1","prettier":"^3.5.3","supertest":"^7.1.0","typescript":"^5.8.3","@types/cors":"^2.8.17","@types/node":"^20.17.0","@types/express":"^5.0.1","node-mocks-http":"^1.16.2","@types/supertest":"^6.0.3","@vitest/coverage-v8":"3.1.1","@silverhand/ts-config":"^6.0.0","@modelcontextprotocol/sdk":"^1.17.1","@silverhand/eslint-config":"^6.0.1","@types/express-serve-static-core":"^5.0.6"},"peerDependencies":{"express":"^5.0.1"},"_npmOperationalInternal":{"tmp":"tmp/mcp-auth_0.2.0_1768971090488_0.9443325685255102","host":"s3://npm-registry-packages-npm-production"}},"1.0.0-beta.1":{"name":"mcp-auth","version":"1.0.0-beta.1","author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"description":"Plug and play auth for Model Context Protocol (MCP) servers","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"type":"module","main":"./lib/index.js","types":"./lib/index.d.ts","exports":{".":{"types":"./lib/index.d.ts","import":"./lib/index.js","default":"./lib/index.js"},"./package.json":"./package.json"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/mcp-auth/js.git","directory":"packages/mcp-auth"},"scripts":{"build":"rm -rf lib/ && tsc -p tsconfig.build.json","prepack":"pnpm run build","dev":"tsc -p tsconfig.build.json --watch --preserveWatchOutput --incremental","test":"vitest","lint":"eslint src"},"engines":{"node":">=20.19.0"},"publishConfig":{"access":"public"},"devDependencies":{"@modelcontextprotocol/server":"^2.0.0","@silverhand/eslint-config":"^6.0.1","@silverhand/ts-config":"^6.0.0","@types/node":"^20.17.0","@vitest/coverage-v8":"3.1.1","eslint":"^8.57.0","nock":"^14.0.4","prettier":"^3.5.3","typescript":"^5.8.3","vitest":"^3.1.1"},"dependencies":{"jose":"^6.2.10"},"peerDependencies":{"@modelcontextprotocol/server":"^2.0.0"},"eslintConfig":{"extends":"@silverhand"},"prettier":"@silverhand/eslint-config/.prettierrc","gitHead":"8e1b3497bfc707f4b13d4b0f4b91e649686fab1c","_id":"mcp-auth@1.0.0-beta.1","bugs":{"url":"https://github.com/mcp-auth/js/issues"},"homepage":"https://github.com/mcp-auth/js#readme","_nodeVersion":"22.23.2","_npmVersion":"11.19.1","dist":{"integrity":"sha512-g4joE9rcvhT+itwvv75UL3+fxdIbQAFUjXqREFtdIXDOKOFfGdnFT5OD150Wh5vGeCKseki+qzBp+zSblftukg==","shasum":"015ce75690b627bb0b3fff946d73b9c74d9c0ecb","tarball":"https://registry.npmjs.org/mcp-auth/-/mcp-auth-1.0.0-beta.1.tgz","fileCount":18,"unpackedSize":75491,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/mcp-auth@1.0.0-beta.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCcTt2C4000dHHiIKAus6u7JUsxA7BIiPAYqS1xODbLogIhAIpchF7ZOuw/39zPrxjc7zRddFXknIfDMYi3Viv5tzAT"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:fef82746-7aa4-4563-a0e6-3b2871aefbf1"}},"directories":{},"maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"},{"name":"xiaoyijun","email":"i@xiaoyijun.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-auth_1.0.0-beta.1_1788166496058_0.6737268817571607"},"_hasShrinkwrap":false}},"time":{"created":"2025-04-03T00:57:10.053Z","modified":"2026-08-31T08:54:56.536Z","0.0.0":"2025-04-03T00:57:10.327Z","0.1.0-beta.0":"2025-05-05T16:53:59.702Z","0.1.0-beta.1":"2025-05-05T17:05:47.394Z","0.1.0-beta.2":"2025-05-05T18:35:39.208Z","0.1.0-beta.3":"2025-05-05T19:07:46.502Z","0.1.0":"2025-05-09T04:32:56.684Z","0.1.1":"2025-05-21T23:52:48.945Z","0.2.0-beta.1":"2025-08-11T05:03:36.693Z","0.2.0":"2026-01-21T04:51:30.626Z","1.0.0-beta.1":"2026-08-31T08:54:56.228Z"},"bugs":{"url":"https://github.com/mcp-auth/js/issues"},"author":{"name":"Silverhand Inc.","email":"contact@silverhand.io"},"license":"MIT","homepage":"https://github.com/mcp-auth/js#readme","keywords":["modelcontextprotocol","mcp","oauth","openid","connect","oidc"],"repository":{"type":"git","url":"git+https://github.com/mcp-auth/js.git","directory":"packages/mcp-auth"},"description":"Plug and play auth for Model Context Protocol (MCP) servers","maintainers":[{"name":"gaosun","email":"gao.npm@gmail.com"},{"name":"xiaoyijun","email":"i@xiaoyijun.com"}],"readme":"# mcp-auth\n\n> The MCP SDK asks you to bring two things: a token verifier and your auth metadata. mcp-auth gives you both, for any OAuth / OIDC provider.\n\n[Docs & tutorials](https://mcp-auth.dev) · [Sample servers](https://github.com/mcp-auth/js/tree/master/packages/sample-servers)\n\nThe MCP TypeScript SDK v2 (`@modelcontextprotocol/server`) ships the entire HTTP layer of MCP authorization itself: `requireBearerAuth`, `verifyBearerToken`, `oauthMetadataResponse`, and official framework adapters like `@modelcontextprotocol/express`. What it leaves to you is provider integration: verifying the access tokens your OAuth 2.0 / OpenID Connect provider issues, and describing that provider in your server's metadata.\n\nThat is exactly what mcp-auth does:\n\n1. **A token verifier**: `MCPAuth` implements the SDK's `OAuthTokenVerifier` interface. It discovers your provider's metadata, fetches its JWKS, and verifies JWT access tokens (signature, issuer, audience, expiration, and the claims MCP servers need), with sensible caching throughout. `mcpAuth.getBearerAuthOptions()` bundles the verifier with the RFC 9728 metadata URL into the SDK's `BearerAuthOptions`, ready for `requireBearerAuth`.\n2. **Your auth metadata**: `mcpAuth.getAuthMetadataOptions()` returns the SDK's `AuthMetadataOptions`, ready to serve the OAuth discovery documents.\n\nIt implements the authorization requirements of the [latest MCP specification](https://modelcontextprotocol.io/specification/latest/basic/authorization) and works with any OAuth 2.0 / OpenID Connect provider that meets them.\n\n## Installation\n\n```bash\nnpm install mcp-auth @modelcontextprotocol/server\n```\n\n`@modelcontextprotocol/server` v2 is a peer dependency. Node.js >= 20; ESM only. Still on MCP SDK v1 (`@modelcontextprotocol/sdk`)? Use [`mcp-auth@0.2`](https://github.com/mcp-auth/js/tree/v0.2.0).\n\n## Get started\n\n```ts\nimport {\n  createMcpHandler,\n  McpServer,\n  oauthMetadataResponse,\n  requireBearerAuth,\n} from '@modelcontextprotocol/server';\nimport { getAuthInfo, MCPAuth } from 'mcp-auth';\n\n// 1. Declare this MCP server and the authorization server it trusts\nconst mcpAuth = new MCPAuth({\n  protectedResourceMetadata: {\n    resource: 'https://api.example.com/mcp',\n    authorizationServer: { issuer: 'https://auth.example.com/oidc', type: 'oidc' },\n    scopesSupported: ['read:notes'],\n  },\n});\n\n// 2. Gate your MCP endpoint: signature, issuer, audience, expiration, and scopes all enforced\nconst gate = requireBearerAuth(mcpAuth.getBearerAuthOptions({ requiredScopes: ['read:notes'] }));\n\n// 3. Read the verified identity in your tools with `getAuthInfo`\nconst handler = createMcpHandler(() => {\n  const server = new McpServer({ name: 'Notes', version: '1.0.0' });\n  server.registerTool('whoami', { description: 'Get the current user' }, (ctx) => {\n    // Pass { requiredScopes: [...] } as the second argument for per-tool authorization\n    const { subject, claims } = getAuthInfo(ctx);\n    return { content: [{ type: 'text', text: JSON.stringify({ subject, claims }) }] };\n  });\n  return server;\n});\n\n// 4. Wire it up (Cloudflare Workers, Deno, Bun, Node.js)\nexport default {\n  async fetch(request: Request): Promise<Response> {\n    if (new URL(request.url).pathname.startsWith('/.well-known/')) {\n      // Serve the OAuth discovery documents\n      const metadata = oauthMetadataResponse(request, await mcpAuth.getAuthMetadataOptions());\n      if (metadata) return metadata;\n    }\n\n    const auth = await gate(request);\n    if (auth instanceof Response) return auth;\n    return handler.fetch(request, { authInfo: auth });\n  },\n};\n```\n\nHead to [mcp-auth.dev](https://mcp-auth.dev) for tutorials and the full documentation. The [sample servers](https://github.com/mcp-auth/js/tree/master/packages/sample-servers) in this repository are complete runnable projects: `whoami` and `todo-manager` as Cloudflare Workers, plus an Express variant built with `@modelcontextprotocol/express`.\n\n## Configuration highlights\n\n- `protectedResourceMetadata` is your RFC 9728 Protected Resource Metadata declaration. Everything in it is published through the SDK's metadata helpers, and the token verifier enforces what it declares: the `aud` claim must match `resource` and the `iss` claim must match the configured authorization server.\n- `authorizationServer` accepts a discovery config (`{ issuer, type }`, metadata fetched lazily and cached, safe for edge runtimes where module-init network calls are not allowed) or a resolved config with metadata (hardcoded or pre-fetched via `fetchServerConfig()`).\n- Audience (`aud`) validation always expects your `resource` identifier and cannot be redirected or disabled: the MCP authorization specification requires access tokens to be bound to the resource they are issued for (RFC 8707), so tokens without a matching `aud` claim are rejected.\n- `jwtVerifyOptions` passes options through to [jose](https://github.com/panva/jose)'s `jwtVerify` for advanced tuning (clock tolerance, required claims, etc.); `issuer` and `audience` are excluded since they always come from the metadata declaration.\n- Verified tokens are surfaced as `McpAuthInfo`, the SDK's `AuthInfo` plus guaranteed `issuer`, `subject`, and the full `claims` payload.\n\n## Opaque access tokens\n\n`MCPAuth` verifies JWT access tokens against your provider's JWKS. Some authorization servers issue opaque access tokens instead: random strings with nothing to verify locally. The two halves of mcp-auth are decoupled, so this case is covered by bringing your own verifier: implement the SDK's `OAuthTokenVerifier` against your server's token introspection endpoint ([RFC 7662](https://datatracker.ietf.org/doc/html/rfc7662)), and keep using the metadata half. The discovery documents, the challenge URL, and `getAuthInfo()` all work unchanged.\n\n```ts\nimport {\n  OAuthError,\n  OAuthErrorCode,\n  requireBearerAuth,\n  type OAuthTokenVerifier,\n} from '@modelcontextprotocol/server';\nimport { MCPAuth, type McpAuthInfo } from 'mcp-auth';\n\nconst issuer = 'https://auth.example.com/oidc';\nconst resource = 'https://api.example.com/mcp';\n\n// The metadata half works exactly as in the example above\nconst mcpAuth = new MCPAuth({\n  protectedResourceMetadata: {\n    resource,\n    authorizationServer: { issuer, type: 'oidc' },\n    scopesSupported: ['read:notes'],\n  },\n});\n\nconst introspectionEndpoint = 'https://auth.example.com/oidc/token/introspection';\n// Most servers require a confidential client (e.g. a machine-to-machine app) to\n// introspect tokens issued to other clients\nconst clientId = 'your-m2m-client-id';\nconst clientSecret = 'your-m2m-client-secret';\n\nconst introspectionVerifier: OAuthTokenVerifier = {\n  async verifyAccessToken(token): Promise<McpAuthInfo> {\n    let response: Response;\n\n    try {\n      response = await fetch(introspectionEndpoint, {\n        method: 'POST',\n        headers: {\n          'content-type': 'application/x-www-form-urlencoded',\n          authorization: `Basic ${btoa(`${clientId}:${clientSecret}`)}`,\n        },\n        body: new URLSearchParams({ token, token_type_hint: 'access_token' }),\n        signal: AbortSignal.timeout(5000),\n      });\n    } catch (error) {\n      /*\n       * A plain `Error`, not an `OAuthError`: the SDK answers 500. The token could not be\n       * verified, which is different from being invalid; a 401 would send a client with a\n       * perfectly fine token into a pointless re-authorization.\n       */\n      throw new Error('Failed to reach the token introspection endpoint.', { cause: error });\n    }\n\n    if (!response.ok) {\n      throw new Error(`Introspection request failed with status ${response.status}.`);\n    }\n\n    const data = (await response.json()) as McpAuthInfo['claims'];\n\n    // The MCP spec still requires these checks; introspection does not exempt them\n    if (data.active !== true) {\n      throw new OAuthError(OAuthErrorCode.InvalidToken, 'The token is not active.');\n    }\n\n    if (!(Array.isArray(data.aud) ? data.aud : [data.aud]).includes(resource)) {\n      throw new OAuthError(OAuthErrorCode.InvalidToken, 'The token audience does not match.');\n    }\n\n    if (typeof data.iss === 'string' && data.iss !== issuer) {\n      throw new OAuthError(OAuthErrorCode.InvalidToken, 'The token issuer is not trusted.');\n    }\n\n    if (typeof data.sub !== 'string' || typeof data.exp !== 'number') {\n      throw new OAuthError(OAuthErrorCode.InvalidToken, 'The token has no `sub` or `exp`.');\n    }\n\n    // The `McpAuthInfo` shape, so `getAuthInfo()` in tool callbacks works unchanged\n    return {\n      token,\n      issuer,\n      subject: data.sub,\n      clientId: typeof data.client_id === 'string' ? data.client_id : '',\n      scopes: typeof data.scope === 'string' ? data.scope.split(' ').filter(Boolean) : [],\n      expiresAt: data.exp,\n      claims: data,\n    };\n  },\n};\n\n// Only the gate changes; the discovery documents still come from `mcpAuth` as shown above\nconst gate = requireBearerAuth({\n  verifier: introspectionVerifier,\n  resourceMetadataUrl: mcpAuth.resourceMetadataUrl,\n  requiredScopes: ['read:notes'],\n});\n```\n\nA few things to know:\n\n- **The endpoint**: some servers advertise it as `introspection_endpoint` in their metadata, others keep it off the public discovery document entirely (e.g. an internal admin API). Configure whatever yours is.\n- **The credentials**: most servers only let authenticated confidential clients introspect tokens issued to other clients; some deployments protect the endpoint at the network level instead. Check your server's policy.\n- **The cost**: every request is an introspection round-trip. That is also the point: revoked tokens are rejected immediately. Add caching only if you accept the revocation delay.\n\n## Join the discussion\n\nJoin the [MCP Auth org discussion](https://github.com/orgs/mcp-auth/discussions) to ask questions or share your feedback.\n","readmeFilename":"README.md"}