Skip to main content
Glama
khandrew1

mcp-use-aps-example

by khandrew1
README.md
# mcp-use + APS authorization example

This standalone example puts the Agent Passport System `aps-mcp-1` profile behind the existing `mcp-use` TypeScript middleware seam. A gateway proxies a `vault_echo` tool and verifies a signed, one-use authorization envelope before `next()` can reach the upstream server.

## Run

```bash
npm install
npm test
npm run dev
```

Open the printed URL to use the built-in mcp-use Inspector.

1. Call `issue_aps_demo_grant` with a message.
2. Copy its structured result into `vault_echo`.
3. Run `vault_echo`; the APS middleware verifies the signature, target, argument hash, expiry, scope, and replay state before dispatch.
4. Run the same request again to see replay rejection before the upstream is called.

## Inspector compatibility

The APS MCP profile normally carries its envelope at:

```text
tools/call.params._meta["org.agent-passport/authorization"]
```

The current Inspector form does not expose arbitrary per-call `_meta`. For interactive demonstration only, this repo accepts the identical envelope as the `apsAuthorization` tool argument, moves it into the namespaced `_meta` entry inside middleware, and removes it before forwarding. A production MCP client should send `_meta` directly.

This localhost demo also treats transport authentication as already established. Production code must configure OAuth and derive that fact from verified transport context (`ctx.auth`).

APS is an independent third-party project and is not part of MCP or mcp-use.