Skip to main content
Glama

oferty-spike-mcp

Spike #1 del proyecto „Oferty Online": ¿el servidor OAuth 2.1 integrado de Supabase Auth (beta) se entiende con la aplicación Claude mediante Dynamic Client Registration?

El código está para tirar. Cero pruebas, cero manejo de errores aparte de lo que diagnostica el propio spike, cero herramientas MCP reales. Al final solo queda una nota con conclusiones.

Qué hay aquí

Archivo

Rol

src/server.js

enrutado HTTP, validación de Host, lazy auth, discovery

src/mcp.js

servidor MCP v2 + herramienta ping() que devuelve la identidad del token

src/verifier.js

dos rutas: Bearer estático (Claude Code) y token Supabase (aplicación Claude)

src/consent.js

página de consentimiento — lo único que escribimos nosotros

src/supabase-metadata.js

obtención de metadatos AS al inicio, fail fast

Usamos SDK v2 (@modelcontextprotocol/server + @modelcontextprotocol/node). @modelcontextprotocol/sdk es la legacy v1 — la mayoría de los tutoriales en la red describen esa.

Related MCP server: Remote MCP Server on Cloudflare

Variables de entorno

Ver .env.example. Las cuatro son obligatorias, el proceso no arranca sin ellas.

Ejecución local

npm ci
APP_ORIGIN=http://localhost:3000 SUPABASE_URL=https://twoj.supabase.co \
  SUPABASE_ANON_KEY=... SPIKE_STATIC_TOKEN=... npm start

Endpoints

  • POST /mcp — Streamable HTTP, stateless

  • GET /.well-known/oauth-protected-resource/mcp — RFC 9728

  • GET /.well-known/oauth-authorization-server — metadatos de Supabase, pasados literalmente

  • GET /oauth/consent?authorization_id=… — página de consentimiento

  • GET /healthz — vitalidad del proceso, a propósito no hace ping a Supabase

Diagnóstico

Sin token, POST /mcp responde 401 con la cabecera WWW-Authenticate que apunta a Protected Resource Metadata — así sabrás que lazy authentication funciona.

Ante la sospecha de un problema con la reconexión del conector (el punto más sospechoso del spike) son útiles supabase.auth.oauth.listGrants() y revokeGrant({ clientId }) — permiten ver y borrar el consentimiento guardado sin tocar la base de datos manualmente.

Related MCP Connectors

  • Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.

  • The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.

  • Remote streamable-HTTP MCP server running on a single Cloudflare Worker. Your assistant gets live Airbnb, Amazon, Booking.com, Google Flights, Maps and Reddit data, social search on X, Instagram and TikTok, the Meta Ad Library, and image/video generation without any keys. Connect your own accounts to let it send WhatsApp or Telegram messages, work an IMAP inbox, manage Meta Ads campaigns and publish to X and LinkedIn. OAuth 2.1 with PKCE; stored credentials are AES-256-GCM encrypted.

  • Minimal streamable HTTP MCP server used for owned-account registry connectivity tests.

Related MCP Servers

  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables Claude.ai to connect to a Hermes MCP server via OAuth 2.1 authorization code flow with PKCE, acting as a reverse proxy and single-user authorization gateway.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables remote MCP server deployment on Cloudflare Workers with OAuth login, supporting tool calling via SSE from clients like MCP Inspector or Claude Desktop.
    -
  • F
    license
    Not graded
    quality
    C
    maintenance
    A proof-of-concept HTTP MCP server requiring OAuth 2.0 authentication before tool use. Demonstrates the full authentication flow with Claude Code, including discovery, client registration, PKCE authorization, and bearer token verification.
    -
  • F
    license
    Not graded
    quality
    B
    maintenance
    A simple HTTP-based MCP server that provides demo tools (get_test_string, echo, check_maintenance), greeting prompts, and test resources, with optional OAuth 2.1 support.
    -