mcpgram-mcp-server
mcpgram-mcp-server
Official MCP server for MCPGRAM — stdio + Streamable HTTP + built-in OAuth 2.1 for Claude.ai, Cursor, and other MCP clients.
Features
MCPGRAM as Authorization Server — DCR, PKCE, authorize, token, revoke
Per-user workspaces — consent selects a workspace; tokens bind to that workspace API key
No external Auth0 / WorkOS / Clerk dependency for MCP OAuth
Flow
Claude → discovery (PRM + AS metadata on this host)
→ POST /register (DCR)
→ GET /authorize (login + workspace + consent)
→ POST /token (code + PKCE)
→ POST /mcp (Bearer access token)
→ workspace toolsEnvironment
Variable | Required | Notes |
| yes | Public origin of this deployment |
| yes | HMAC for clients/codes/tokens (≥16 chars) |
| yes | Consent login + key issuance |
| yes | Browser consent session |
| yes | Issue workspace API keys server-side |
| recommended | Encrypt stored workspace keys |
| yes | MCPGRAM API ( |
Claude connector URL
https://mcpgram-mcp-server.vercel.app/mcpClaude will discover OAuth on this same origin (/register, /authorize, /token).
Isolation
Each user’s OAuth token only carries their selected workspace API key. User A never loads User B’s tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/Aryan418-dev/mcpgram-mcp-server'
If you have feedback or need assistance with the MCP directory API, please join our Discord server