oferty-spike-mcp
oferty-spike-mcp
项目 „Oferty Online" 的 Spike #1:Supabase Auth(测试版)内置的 OAuth 2.1 服务器能否通过 Dynamic Client Registration 与 Claude 应用对接。
代码仅供丢弃。 零测试,除 spike 自身诊断外零错误处理,零真实 MCP 工具。完成后只留下一份结论笔记。
这里有什么
文件 | 作用 |
| HTTP 路由、 |
| MCP v2 服务器 + 返回令牌身份的 |
| 两条路径:静态 Bearer(Claude Code)和 Supabase 令牌(Claude 应用) |
| 同意页面——唯一我们自己写的东西 |
| 启动时获取 AS 元数据,快速失败 |
我们使用 SDK v2(@modelcontextprotocol/server + @modelcontextprotocol/node)。
@modelcontextprotocol/sdk 是旧版 v1——网上大多数教程描述的都是它。
Related MCP server: Remote MCP Server on Cloudflare
环境变量
见 .env.example。四个都是必需的,没有它们进程不会启动。
本地运行
npm ci
APP_ORIGIN=http://localhost:3000 SUPABASE_URL=https://twoj.supabase.co \
SUPABASE_ANON_KEY=... SPIKE_STATIC_TOKEN=... npm start端点
POST /mcp— Streamable HTTP,无状态GET /.well-known/oauth-protected-resource/mcp— RFC 9728GET /.well-known/oauth-authorization-server— Supabase 元数据,原样传递GET /oauth/consent?authorization_id=…— 同意页面GET /healthz— 进程存活性,故意不 ping Supabase
诊断
不带令牌调用 POST /mcp 时返回 401,带有 WWW-Authenticate 头指向
Protected Resource Metadata——由此可以判断懒认证是否生效。
若怀疑连接器重连问题(spike 中最可疑的点),
supabase.auth.oauth.listGrants() 和 revokeGrant({ clientId }) 很实用——它们能
查看和删除已保存的同意,而无需手动操作数据库。
This server cannot be deployed
Maintenance
Related MCP Connectors
Experimental MCP server for current empirical verification of explicit public HTTPS endpoint claims.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Remote streamable-HTTP MCP server running on a single Cloudflare Worker. Your assistant gets live Airbnb, Amazon, Booking.com, Google Flights, Maps and Reddit data, social search on X, Instagram and TikTok, the Meta Ad Library, and image/video generation without any keys. Connect your own accounts to let it send WhatsApp or Telegram messages, work an IMAP inbox, manage Meta Ads campaigns and publish to X and LinkedIn. OAuth 2.1 with PKCE; stored credentials are AES-256-GCM encrypted.
Minimal streamable HTTP MCP server used for owned-account registry connectivity tests.
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceEnables Claude.ai to connect to a Hermes MCP server via OAuth 2.1 authorization code flow with PKCE, acting as a reverse proxy and single-user authorization gateway.-
- FlicenseNot gradedqualityCmaintenanceEnables remote MCP server deployment on Cloudflare Workers with OAuth login, supporting tool calling via SSE from clients like MCP Inspector or Claude Desktop.-
- FlicenseNot gradedqualityCmaintenanceA proof-of-concept HTTP MCP server requiring OAuth 2.0 authentication before tool use. Demonstrates the full authentication flow with Claude Code, including discovery, client registration, PKCE authorization, and bearer token verification.-
- FlicenseNot gradedqualityBmaintenanceA simple HTTP-based MCP server that provides demo tools (get_test_string, echo, check_maintenance), greeting prompts, and test resources, with optional OAuth 2.1 support.-