Skip to main content
Glama
idmpotent2025

Inventory MCP Server

Invoice MCP Server

A Next.js web app deployed on Vercel that acts as an MCP (Model Context Protocol) server for inventory management. Demonstrates all Auth0 for MCP capabilities via the @auth0/ai-vercel SDK.

Auth0 for MCP Capabilities

Capability

Tool

What it does

JWT Bearer Token

all tools

withMcpAuth + jose JWKS verification validates the Auth0 access token on every request

FGA (Fine-Grained Authorization)

addItem

withFGA checks user:<sub> writer inventory:default before adding items

FGA + CIBA Step-up

deleteItem

withFGA checks user:<sub> owner inventory:<id> AND withAsyncAuthorization sends a CIBA push for out-of-band approval

Token Vault

commentItem

withTokenVault fetches a federated Slack access token stored in Auth0 Token Vault

Related MCP server: mcp_auth_server

MCP Endpoint

POST/GET/DELETE https://<your-app>.vercel.app/api/mcp

All requests require:

Authorization: Bearer <Auth0 access_token>

The access token must have the read:inventory scope (plus write:inventory for mutations).

Tools

listInventory

Returns all inventory items. No extra authorization beyond the bearer token.

addItem

{ "name": "Widget X", "quantity": 50, "price": 12.99 }

Requires FGA relation: user:<sub> writer inventory:default

deleteItem

{ "id": "item-001" }

Requires:

  1. FGA relation: user:<sub> owner inventory:item-001

  2. CIBA approval — the user receives a push notification and must approve

commentItem

{ "id": "item-001", "comment": "Reorder ASAP" }

Saves the comment and posts a Slack message via Auth0 Token Vault (user must have linked Slack account).

Setup

1. Auth0 Tenant

  1. Create an API in Auth0 with audience matching AUTH0_AUDIENCE, with scopes read:inventory and write:inventory.

  2. Create an M2M application with Client Credentials grant for CIBA token exchange and Token Vault operations. Note the Client ID and Secret.

  3. Enable Auth0 Fine Grained Authorization and create a store. Configure tuples for your test users:

    user:<sub> writer inventory:default
    user:<sub> owner inventory:item-001
  4. Enable CIBA on your tenant (requires a push notification provider).

  5. Configure a Slack social connection in Auth0 with chat:write scope and enable Token Vault storage.

2. Environment Variables

Copy .env.example to .env.local and fill in your values:

cp .env.example .env.local

Add the same variables in your Vercel project settings (Settings → Environment Variables).

Optional variable for Slack notifications:

SLACK_CHANNEL_ID=C0123456789
SLACK_REFRESH_TOKEN=xoxe-...   # fallback for testing; normally read from JWT claims

3. Deploy to Vercel

npm install
vercel deploy

Or connect your GitHub repo to Vercel for automatic deployments.

4. Connect an MCP Client

{
  "mcpServers": {
    "inventory": {
      "url": "https://<your-app>.vercel.app/api/mcp",
      "headers": {
        "Authorization": "Bearer <access_token>"
      }
    }
  }
}

Get an access token via the Auth0 Device Flow, Authorization Code flow, or your preferred grant.

FGA Model

Minimum required tuples for testing:

type user
type inventory
  relations
    define writer: [user]
    define owner: [user]

Create tuples:

fga tuple write --store-id $FGA_STORE_ID \
  --user user:<your-sub> \
  --relation writer \
  --object inventory:default

fga tuple write --store-id $FGA_STORE_ID \
  --user user:<your-sub> \
  --relation owner \
  --object inventory:item-001

Known Limitations

  • CIBA store: The in-memory MemoryStore (default in Auth0AI) does not persist across Vercel cold starts. For production, configure a persistent store such as @auth0/ai-redis backed by Vercel KV or Upstash Redis.

  • Inventory store: In-memory; resets on cold start. Replace with Vercel Postgres, Neon, or similar for persistence.

Local Development

npm install
cp .env.example .env.local
# fill in .env.local
npm run dev

MCP server will be available at http://localhost:3000/api/mcp.

F
license - not found
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    D
    maintenance
    A remote MCP server implementation that demonstrates authentication and authorization capabilities using OAuth 2.1. This is a workshop project for learning how to build secure MCP servers with user authentication.
    Last updated
    28,807
    MIT
  • F
    license
    -
    quality
    C
    maintenance
    A proof-of-concept MCP server implementing OAuth 2.1 authorization with CIMD client registration and PKCE, demonstrating protected resource access and step-up authentication.
    Last updated

View all related MCP servers

Related MCP Connectors

  • MCP server for Argo RPG Platform — connects AI assistants to campaign data via OAuth2

  • Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.

  • MCP server for verifying EUDI/Talao wallet data via OIDC4VP (pull) for AI agents.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/idmpotent2025/inventory-mcp-server'

If you have feedback or need assistance with the MCP directory API, please join our Discord server