authshore
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@authshoreCreate a user pool named main and add a user with email test@example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
as
Auth infrastructure for coding agents — user pools, secrets vault, token management. As easy as git.
git for your code. as for your auth.
Your agent can scaffold a whole app in an afternoon — then stalls the moment it needs auth. It hardcodes secrets into .env files it later commits, rolls its own JWT handling, and leaves you wiring up Cognito by hand. AuthShore is the auth layer your agent runs itself: one install, and it provisions user pools, stores secrets encrypted, and mints, validates and refreshes tokens — from the terminal, with no console to click through.
Works with: Claude Code · Cursor · Cline · Windsurf · Aider · Codex · any MCP client
See It In Action
Real terminal sessions against the live API — click a GIF for the full video.
Zero to auth in 60s | Secrets vault | Tokens & pools |
|
|
|
More demos: authshore.ai/#demo
Related MCP server: Enterprise MCP Gateway and Tool Registry
Install
npm install -g authshoreThe npm package is authshore; the command is as.
Quick Start
# 1. Create a project — free plan, API key active immediately, no card
as signup my-project --email you@example.com --local
# 2. Create a user pool
as pool create main
# 3. Store a secret (encrypted at rest, versioned)
as secret set DATABASE_URL "postgres://user:pass@host:5432/db"
# 4. Sign up a user in your pool
as pool auth signup main --email user@example.com --password SecurePass123!
# Full reference
as helpUser Pools — Cognito without the console
Every project gets isolated user pools your agent manages from the terminal: create pools, add users, run full signup/signin flows that return real JWT pairs.
as pool create main # create a pool
as pool list # list pools
as pool users <id> # list users in a pool
as pool user add <id> --email E --password P
as pool auth signup <id> --email E --password P # returns access + refresh tokens
as pool auth signin <id> --email E --password PSecrets Vault — stop pasting keys into .env
Encrypted, versioned key-value storage scoped to your project. Your agent stores third-party keys once and reads them at deploy time — nothing sensitive left sitting in the repo.
as secret set STRIPE_KEY "sk_..." --env production
as secret get STRIPE_KEY # decrypted read
as secret list
as secret versions STRIPE_KEY # full version history
as secret delete STRIPE_KEYTokens — mint, validate, refresh, revoke
The JWT plumbing agents usually hand-roll, done right once.
as token validate <jwt> # verify signature + expiry, show claims
as token refresh <refresh-token> # rotate the pair
as token revoke <token> # kill a compromised tokenMCP Server
Prefer tools over a CLI? as ships an MCP server. Point Claude Code (or any MCP client) at it and your agent gets 18 native tools: pools, users, secrets, tokens, project status.
claude mcp add authshore --env AUTHSHORE_API_KEY=as_your_key_here -- as mcp-serveFor clients that use a JSON config (Cline, Cursor, Windsurf), pass your API key via the AUTHSHORE_API_KEY environment variable. The MCP server runs outside your project directory, so it will not pick up .authshore/config.json:
{
"mcpServers": {
"authshore": {
"command": "as",
"args": ["mcp-serve"],
"env": { "AUTHSHORE_API_KEY": "as_your_key_here" }
}
}
}No key yet? as signup my-project --email you@example.com provisions one in seconds — free plan, no card.
Remote MCP — zero install
No CLI at all? Claude Web, Claude Desktop, Raycast, or any hosted MCP client can connect straight to our remote server. Same 18 tools, nothing to install:
URL: https://mcp.authshore.ai/sse
Auth: Authorization: Bearer YOUR_API_KEYNo key? Connect without one: the remote server starts in onboarding mode with an authshore_signup tool that provisions your account and unlocks everything in the same session.
Features
User pools - isolated pools per project, full signup/signin flows, real JWT pairs
Secrets vault - encrypted at rest, versioned, environment-scoped
Tokens - validate, refresh, revoke from the terminal
MCP server - 18 tools, local (
as mcp-serve) or fully remote (mcp.authshore.ai): Claude Code, Claude Web, Cursor, Raycast, any MCP clientAgent-first CLI -
--jsonon every command for programmatic parsingProject-local config -
.authshore/config.json, auto-loaded, gitignore-friendly
Pricing: free plan with an instantly-active API key — no card, no trial clock. Paid plans (Starter $9 / Pro $29 / Scale $99 per month) come with a 7-day free trial via secure Stripe checkout. Details.
Config
as login --key YOUR_KEY --local # saves to .authshore/config.json (project-local)
as config # show active config
as me # identity check: which project am I?API key is resolved in this order (highest priority first):
--keyflagAUTHSHORE_API_KEYenvironment variable./.authshore/config.json(project-local)~/.authshore/config.json(global)
Add .authshore/ to your .gitignore.
Agent Integration
Add to your CLAUDE.md, .cursorrules, .clinerules, .windsurfrules, or AGENTS.md:
## Auth
This project uses AuthShore for auth: user pools, secrets, tokens.
Use the `as` CLI. Config is in .authshore/config.json (auto-loaded).
If not configured: as login --local --key YOUR_KEY
Run `as help` for the full command reference. Run `as me` before any writes.Why this exists
Every agent-built app hits the same wall: auth. I watched my agents hardcode secrets, reinvent JWT refresh, and stall on Cognito consoles they can't click. So I built the auth layer the agent runs itself. It's early and I'm iterating fast: if something's rough or missing, open an issue — I read every one.
Documentation
License
Proprietary - Tyga.Cloud Ltd. See LICENSE.
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityDmaintenanceMCP server for enterprise authentication and authorization — JWT validation, OIDC token inspection, OAuth 2.0 introspection, and role-based access control for AI agents.Last updated8MIT
- Alicense-qualityCmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.Last updated1MIT
- Alicense-qualityBmaintenanceMCP-native credential vault that enables AI agents to authenticate with external services without exposing secrets, supporting bearer, basic, OAuth2, and other auth patterns via MCP tools.Last updated6MIT
- Flicense-qualityCmaintenanceEnables AI agents and MCP clients to securely store, retrieve, and manage encrypted credentials without hardcoding API keys.Last updated
Related MCP Connectors
Hash passwords with bcrypt and issue/verify JWT session tokens over A2A + MCP.
Encrypted secret store and rotation for autonomous agent credentials
Artifact store for AI agents. Hosted OAuth at mcp.artifacta.io/mcp; local stdio via npm/PyPI.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jyswee/authshore'
If you have feedback or need assistance with the MCP directory API, please join our Discord server


