Skip to main content
Glama
Clamepending

ottoauthMCP

by Clamepending
README.md
# ottoauthMCP

Standalone MCP stdio server that proxies tool calls to Ottoauth HTTP endpoints.

## Features

- Discovers service endpoints from `GET /api/services` docs.
- Registers dynamic MCP tools per endpoint.
- Refreshes discovered tools once every hour.
- Includes a generic passthrough tool: `ottoauth_http_request`.
- Includes a built-in account creation tool: `ottoauth_create_account`.
- Runs an Ottoauth webhook receiver and relays incoming events to an agent gateway with retries.

## Run

```bash
npm install
OTTOAUTH_BASE_URL=http://localhost:3000 npm start
```

Webhook receiver defaults:
- host: `127.0.0.1`
- port: `3789`
- path: `/webhooks/ottoauth`

Important env vars:
- `OTTOAUTH_WEBHOOK_SECRET` (recommended; validates `x-ottoauth-signature`)
- `OTTOAUTH_WEBHOOK_ALLOW_UNSIGNED=1` (dev only)
- `OTTOAUTH_WEBHOOK_PORT` / `OTTOAUTH_WEBHOOK_HOST` / `OTTOAUTH_WEBHOOK_PATH`
- `AGENT_GATEWAY_URL` (relay destination)
- `AGENT_GATEWAY_AUTH_TOKEN` (optional bearer token to gateway)
- `WEBHOOK_RETRY_BASE_MS` (default `2000`)
- `WEBHOOK_RETRY_MAX` (default `8`)
- `WEBHOOK_EVENT_STORE_PATH` (defaults to `.ottoauth-webhook-events.json` in cwd)

## Tests

```bash
npm test
```

Test coverage includes:
- parser and normalization edge cases
- timeout and forwarding behavior
- webhook signature, dedupe, retries, dead-letter
- MCP stdio end-to-end flow
- integration test using simple demo agent script from neighboring `autoauth` repo

## MCP client config example

```json
{
  "mcpServers": {
    "ottoauth": {
      "command": "node",
      "args": ["/absolute/path/to/ottoauthMCP/src/index.mjs"],
      "env": {
        "OTTOAUTH_BASE_URL": "https://your-ottoauth-domain.com"
      }
    }
  }
}
```

TDQS

A3.6/5.0

Scored across 7 tools

Disambiguation4/5

The webhook-specific tools are clearly distinct in purpose, and the generic passthrough tool explicitly defers to endpoint-specific tools. However, webhook_status and webhook_list_events both involve event counts/status, which could cause some initial confusion.

Naming Consistency3/5

Most tools use snake_case with a domain prefix, but the pattern is inconsistent: some are verb-first (ottoauth_create_account), some are noun-phrases (webhook_status), and ottoauth_http_request breaks the verb_noun convention. The mixed prefixes make the set feel less uniform.

Tool Count5/5

Seven tools is a well-scoped size for this server. Each tool covers a meaningful operation without redundancy, and the generic passthrough fills edge cases without bloating the surface.

Completeness4/5

The webhook event lifecycle is well covered with list, get, replay, and gateway configuration, plus account creation. Minor gaps exist such as no explicit account deletion or webhook clearing, but the generic HTTP passthrough mitigates dead ends.

Maintenance

ActivityInactive
ResponsivenessNo issues