oferty-spike-mcp
oferty-spike-mcp
Spike #1 des Projekts „Oferty Online": Ob der eingebaute OAuth-2.1-Server von Supabase Auth (Beta) sich über Dynamic Client Registration mit der Claude-App verständigen kann.
Der Code ist Wegwerfcode. Keine Tests, keine Fehlerbehandlung außer dem, was der Spike selbst diagnostiziert, keine echten MCP-Tools. Nach der Ausführung bleibt nur eine Notiz mit den Erkenntnissen.
Was hier drin ist
Datei | Rolle |
| HTTP-Routing, |
| MCP-v2-Server + |
| zwei Pfade: statisches Bearer (Claude Code) und Supabase-Token (Claude-App) |
| Zustimmungsseite – das Einzige, das wir selbst schreiben |
| Abruf der AS-Metadaten beim Start, Fail Fast |
Wir verwenden SDK v2 (@modelcontextprotocol/server + @modelcontextprotocol/node).
@modelcontextprotocol/sdk ist Legacy v1 – die meisten Tutorials im Netz beschreiben genau diese.
Related MCP server: Remote MCP Server on Cloudflare
Umgebungsvariablen
Siehe .env.example. Alle vier sind erforderlich, der Prozess startet ohne sie nicht.
Lokale Ausführung
npm ci
APP_ORIGIN=http://localhost:3000 SUPABASE_URL=https://twoj.supabase.co \
SUPABASE_ANON_KEY=... SPIKE_STATIC_TOKEN=... npm startEndpunkte
POST /mcp— Streamable HTTP, zustandslosGET /.well-known/oauth-protected-resource/mcp— RFC 9728GET /.well-known/oauth-authorization-server— Supabase-Metadaten, wörtlich durchgereichtGET /oauth/consent?authorization_id=…— ZustimmungsseiteGET /healthz— Lebensfähigkeit des Prozesses, pingt bewusst kein Supabase an
Diagnose
Ohne Token antwortet POST /mcp mit 401 und einem WWW-Authenticate-Header, der auf die Protected Resource Metadata verweist – daran erkennst du, dass Lazy Authentication funktioniert.
Bei Verdacht auf ein Problem mit dem Reconnect des Connectors (der verdächtigste Punkt des Spikes) sind supabase.auth.oauth.listGrants() und revokeGrant({ clientId }) nützlich – sie erlauben, die gespeicherte Zustimmung zu sehen und zu löschen, ohne die Datenbank manuell anzufassen.
This server cannot be deployed
Maintenance
Related MCP Connectors
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Remote streamable-HTTP MCP server running on a single Cloudflare Worker. Your assistant gets live Airbnb, Amazon, Booking.com, Google Flights, Maps and Reddit data, social search on X, Instagram and TikTok, the Meta Ad Library, and image/video generation without any keys. Connect your own accounts to let it send WhatsApp or Telegram messages, work an IMAP inbox, manage Meta Ads campaigns and publish to X and LinkedIn. OAuth 2.1 with PKCE; stored credentials are AES-256-GCM encrypted.
Minimal streamable HTTP MCP server used for owned-account registry connectivity tests.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables Claude.ai to connect to a Hermes MCP server via OAuth 2.1 authorization code flow with PKCE, acting as a reverse proxy and single-user authorization gateway.-
- FlicenseNot gradedqualityCmaintenanceEnables remote MCP server deployment on Cloudflare Workers with OAuth login, supporting tool calling via SSE from clients like MCP Inspector or Claude Desktop.-
- FlicenseNot gradedqualityCmaintenanceA proof-of-concept HTTP MCP server requiring OAuth 2.0 authentication before tool use. Demonstrates the full authentication flow with Claude Code, including discovery, client registration, PKCE authorization, and bearer token verification.-
- FlicenseNot gradedqualityBmaintenanceA simple HTTP-based MCP server that provides demo tools (get_test_string, echo, check_maintenance), greeting prompts, and test resources, with optional OAuth 2.1 support.-