JavaScript MCP Auth Server
README.md
# JavaScript MCP Auth Server
This package shows the remote MCP auth boundary in JavaScript:
- Express HTTP server
- MCP Streamable HTTP transport at `/mcp`
- Protected Resource Metadata
- Bearer token middleware
- Keycloak token introspection
- audience validation
- `mcp:tools` scope enforcement
- protected `add_numbers` and `server_status` tools
## Run
```bash
pnpm mcp-auth-server-js install
cp .env.example .env
pnpm mcp-auth-server-js demo:keycloak
pnpm mcp-auth-server-js start
```
For the demo, configure Keycloak with:
- client scope: `mcp:tools`
- MCP server confidential client: `mcp-server`
- demo client/user for obtaining an access token
- token audience: `http://localhost:3000/mcp`
## Demo Scripts
```bash
pnpm mcp-auth-server-js demo:no-token
pnpm mcp-auth-server-js demo:metadata
pnpm mcp-auth-server-js demo:get-token
pnpm mcp-auth-server-js demo:call-tool
pnpm mcp-auth-server-js demo:bad-scope
```
The important point is the failure order:
1. no token returns `401` with `WWW-Authenticate`
2. metadata tells the client where auth lives
3. token introspection rejects inactive tokens
4. audience validation rejects tokens for another API
5. scope validation rejects tokens without `mcp:tools`
This server cannot be deployed
Maintenance
ActivityInactive
ResponsivenessNo issues