mcp-oidc-proxy
Related Servers
Alternatives to mcp-oidc-proxy
No user-submitted related servers found.
Related Servers
- FlicenseNot gradedqualityCmaintenanceEnables secure MCP tool calls (add and multiply numbers) by validating OAuth2 tokens via Keycloak token introspection.-
- FlicenseNot gradedqualityDmaintenanceDemonstrates MCP remote authentication boundary with OAuth 2.0, Keycloak token introspection, audience and scope validation, and protected tools.-
- AlicenseNot gradedqualityCmaintenanceSecures MCP tools as an OAuth 2.1 resource server, validating short-lived delegated tokens, enforcing policy-as-code, and auditing AI agent actions.MIT
- AlicenseNot gradedqualityCmaintenanceEnables MCP clients to authenticate through Convex OAuth Provider, verifying access tokens and exposing a whoami tool for retrieving the authenticated user's identity and scopes.MIT
- FlicenseNot gradedqualityBmaintenanceEnables an MCP server with OAuth authentication, protecting tools like user CRUD operations behind session tokens obtained through a browser-based authentication flow.-
- AlicenseNot gradedqualityBmaintenanceEnables deploying a remote MCP server with OAuth 2.1 resource-server authorization, protecting tools behind validated bearer tokens and RFC 9728 discovery.MIT
TDQS
Scored across 26 tools
Every tool targets a distinct resource and action with clear descriptions that explicitly disambiguate similar pairs (e.g., decode_token vs verify_token, create_user vs create_persona_user). No two tools have overlapping purposes.
All tool names follow a consistent verb_noun pattern in snake_case, using standard verbs like get, list, create, update, delete, rotate, and save. Minor variations (list_users vs get_user) reflect conventional list-vs-fetch semantics.
At 26 tools, the server exceeds the 25-tool threshold for 'too many' defined in the rubric. While the broad scope of an OIDC proxy justifies many operations, the count is above the well-scoped range and may overwhelm an agent with options.
The tool set provides comprehensive coverage: CRUD for users and clients, token generation and verification, key management, audit logging, and config lifecycle (validate, reload, save). Minor gaps exist (e.g., no granular audit log deletion or token introspection), but they do not create dead ends.