MCP OAuth 2.1 Authorization Auditor
audit_mcp_oauthAudit OAuth 2.1 authorization for MCP servers by validating RFC 9728 metadata, checking RFC 8707 audience binding, and assessing token-passthrough and confused-deputy risks.
Instructions
Audit MCP OAuth 2.1 authorization: validate RFC 9728 protected-resource-metadata, check RFC 8707 audience binding, and assess token-passthrough / confused-deputy risk. Use when a developer is securing an MCP server's authorization. Renders the interactive AINumbers tool as a widget; inputs are applied via the AIN Bridge and the tool runs client-side (zero PII, zero network).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| inputs | No | Map of tool input element IDs to values (see manifest input_schema). Applied via AIN Bridge prefill. |