Skip to main content
Glama
kabirrajsingh

JavaScript MCP Auth Server

README.md
# JavaScript MCP Auth Server


This package shows the remote MCP auth boundary in JavaScript:

- Express HTTP server
- MCP Streamable HTTP transport at `/mcp`
- Protected Resource Metadata
- Bearer token middleware
- Keycloak token introspection
- audience validation
- `mcp:tools` scope enforcement
- protected `add_numbers` and `server_status` tools

## Run

```bash
pnpm mcp-auth-server-js install
cp .env.example .env
pnpm mcp-auth-server-js demo:keycloak
pnpm mcp-auth-server-js start
```

For the demo, configure Keycloak with:

- client scope: `mcp:tools`
- MCP server confidential client: `mcp-server`
- demo client/user for obtaining an access token
- token audience: `http://localhost:3000/mcp`

## Demo Scripts

```bash
pnpm mcp-auth-server-js demo:no-token
pnpm mcp-auth-server-js demo:metadata
pnpm mcp-auth-server-js demo:get-token
pnpm mcp-auth-server-js demo:call-tool
pnpm mcp-auth-server-js demo:bad-scope
```

The  important point is the failure order:

1. no token returns `401` with `WWW-Authenticate`
2. metadata tells the client where auth lives
3. token introspection rejects inactive tokens
4. audience validation rejects tokens for another API
5. scope validation rejects tokens without `mcp:tools`