mcp-auth-proxy
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-auth-proxyconnect to https://mcp.company.com/api with client ID my-app"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
mcp-auth-proxy
Stdio-to-HTTP MCP proxy with OAuth 2.1 authentication (PKCE + browser login).
Bridges the gap when your LLM harness only supports stdio MCP servers but the remote MCP server requires OAuth (e.g., Microsoft Entra ID).
LLM Harness (stdio only)
↕ stdin/stdout (JSON-RPC)
mcp-auth-proxy
↕ Streamable HTTP + Bearer token
Remote MCP Server (OAuth-protected)Features
RFC 9728 discovery — auto-discovers authorization server and scopes from the MCP server's protected resource metadata
OAuth 2.1 + PKCE — browser-based login, no client secrets needed (public client)
Random callback port — each instance uses a random port, safe to run multiple instances simultaneously
Auto token refresh — handled transparently by the SDK transport
In-memory only — tokens are never written to disk
Full proxy — tools, resources, and prompts are all proxied
Related MCP server: outsystems-mcp-relay
Installation
⚠️ This package is not published on npm. Install from source using
npm link.
git clone https://github.com/manio143/mcp-stdio-proxy.git
cd mcp-stdio-proxy
npm install
npm run build
npm linkUsage
# Basic — discovers client ID from server metadata
mcp-auth-proxy https://mcp.company.com/api
# With explicit client ID
mcp-auth-proxy https://mcp.company.com/api --clientId=my-app-client-idIn MCP client config (e.g., Claude Desktop, VS Code)
{
"mcpServers": {
"my-server": {
"command": "mcp-auth-proxy",
"args": ["https://mcp.company.com/api", "--clientId=my-app-id"]
}
}
}How authentication works
Proxy probes the remote MCP endpoint → gets
401Parses
WWW-Authenticateheader for resource metadata URL (RFC 9728)Fetches protected resource metadata → finds authorization server + scopes
Fetches authorization server metadata (RFC 8414 / OIDC Discovery)
Opens browser for OAuth 2.1 authorization code flow with PKCE
Receives callback on
http://localhost:{random-port}/callbackExchanges code for tokens
All subsequent requests include
Authorization: Bearer <token>Token refresh happens automatically when tokens expire
Client ID resolution
If
--clientIdis provided, uses thatIf the server's protected resource metadata advertises a client ID, uses that
If the server supports dynamic client registration (RFC 7591), registers automatically
Otherwise, exits with an error
Requirements
Node.js ≥ 20
A browser for the OAuth login flow
The remote MCP server must support Streamable HTTP transport
Security
Tokens held in memory only — process exit clears them
PKCE prevents authorization code interception
Callback server binds to
127.0.0.1onlyRandom port prevents port conflicts and prediction
License
MIT
This server cannot be deployed
Maintenance
Related MCP Connectors
StremAI MCP: shared memory for AI coding agents. Connected agents can recall. OAuth + local stdio.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Remote MCP server exposing SMI Aware tools, resources, and skills over Streamable HTTP.
Access Kernel's cloud-based browsers and app actions via MCP (remote HTTP + OAuth).
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceBridge that lets stdio-only MCP clients connect to remote MCP servers with OAuth and other auth support, enabling local clients to use remote, authorized MCP servers.60 npm54MIT
- AlicenseNot gradedqualityBmaintenanceEnables MCP clients to connect to remote servers that have OAuth issuer mismatches (e.g., OutSystems) by relaying stdio and handling OAuth flows with optional issuer override.8 npmMIT
- FlicenseNot gradedqualityCmaintenanceEnables local MCP clients to access tools from a remote FastMCP server over stdio, handling OAuth authentication and Streamable HTTP communication.-
- AlicenseNot gradedqualityBmaintenanceEnables stdio-only MCP clients to access Orla's remote Streamable HTTP MCP server by relaying JSON-RPC and managing the OAuth session.90 npmMIT