A
licenseNot graded
qualityB
maintenanceEnables MCP clients that can only send a fixed Authorization header to reach OAuth 2.1-protected MCP servers, by running a loopback proxy that handles RFC 9728 discovery, PKCE login, and silent token refresh so no pasted JWT is ever needed. The client keeps a stable local token while the rotating OAuth credentials stay in the gateway's state file.
MIT