Skip to main content
Glama

todo-mcp-server

The same todo app served four ways, to isolate what changes when you stop hand-writing MCP tools and serve a tRPC router instead.

MCP tools by hand

tRPC router

no auth

1_simple

3_trpc2mcp

auth

2_authenticated

4_trpc2mcp_authed

Shared at the root, so each stage is only its routing layer: services.ts (the todo domain), auth.ts (bearer middleware + tRPC context), trpc-mcp.ts (the tRPC → MCP adapter, adapted from Jacse/trpc-mcp).

TypeScript on Bun, Express, no build step.

Run

bun install
bun run start:simple          # stdio
bun run start:authenticated   # :3000/mcp
bun run start:trpc            # :3001/trpc
bun run start:trpc-mcp        # stdio, same router as start:trpc
bun run start:trpc-authed     # :3002 — /trpc and /mcp, one router, one gate

The bearer token is the user id; alice is the only one with the premium scope.

Related MCP server: Stytch Consumer TODO MCP Server

The idea

Opt a procedure in with one .meta() key and trpc-mcp.ts walks the router and registers it as a tool. No meta.mcp (see stats) means it stays tRPC-only.

addTodo: t.procedure
  .meta({ mcp: { enabled: true, name: "add_todo", description: "Add a new todo item" } })
  .input(z.object({ text: z.string().describe("Todo text") }))
  .mutation(({ input }) => Todos.add(user, input.text)),

Auth then only gets written once. 2_authenticated/ reads extra.authInfo in every handler and gates export_todos inline; 4_trpc2mcp_authed/ does both in tRPC middleware, and the /trpc and /mcp mounts inherit it from the same req.auth — see examples/4_trpc2mcp_authed/server.ts.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    F
    maintenance
    A remote MCP server (Node.js/TypeScript) deployed on Azure Container Apps that provides todo list management tools with JWT authentication and role-based access control.
    49
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    An MCP server that enables AI agents to manage a TODO list with user authentication via Stytch. It provides tools for creating, reading, updating, and deleting TODO items while handling identity and authorization.
    27
    MIT
  • F
    license
    Not graded
    quality
    D
    maintenance
    A production-ready MCP server that authenticates agents via OAuth 2.1 Bearer tokens, validates JWTs with JWKS, enforces tool-level scopes and roles, and logs the full delegation chain.
    -