Atlas / MCP servers / christian-posta / Auth Step-by-Step

Auth Step-by-StepBLOCK

mcp/christian-posta/auth-step-by-step

Step by step walkthrough of an MCP Authorization implementation

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
—
Stars
62
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This repository demonstrates building an MCP (Model Context Protocol) server with HTTP transport and JWT authentication, progressing through iterative steps.

This repo is a companion to the in-depth, step-by-step blog posts on "MCP Authorization". See the following:

Part 4 (late addition to the series): MCP Authorization With Dynamic Client Registration

MCP Authorization Specification Requirements

The table below shows support for OAuth RFCs required by the MCP authorization specification across major identity providers.

RFC Requirements Summary:

  • PKCE: Proof Key for Code Exchange (OAuth 2.1 requirement)
  • RFC 8414: OAuth 2.0 Authorization Server Metadata
  • RFC 7591: OAuth 2.0 Dynamic Client Registration Protocol
  • RFC 8707: Resource Indicators for OAuth 2.0

Overview

The project shows how to build a secure MCP server with:

  • FastAPI-based HTTP transport
  • JWT token authentication
  • OAuth 2.0 metadata endpoints
  • Scope-based authorization
  • Role-based access control
Read from source at commit 6658b52abdb2OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-http --env KEYCLOAK_REALM=${KEYCLOAK_REALM} --env KEYCLOAK_URL=${KEYCLOAK_URL} -- uvx mcp-http
claude-desktop
{
  "mcpServers": {
    "mcp-http": {
      "command": "uvx",
      "args": [
        "mcp-http"
      ],
      "env": {
        "KEYCLOAK_REALM": "${KEYCLOAK_REALM}",
        "KEYCLOAK_URL": "${KEYCLOAK_URL}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
echoreadEcho a message
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (12 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (16)

CRITICALHard-coded secrets · secret.private_key · CWE-798, CWE-321
mcp_private_key.pem:1
-----BEGIN PRIVATE KEY-----
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
generate_token.py:165
print(f"🎫 Token: {token_info['token']}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
generate_token.py:190
print(f"🎫 Token: {token}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
keycloak/setup_keycloak.py:852
print(f"    - Client secret: {secret}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp_http/step10.py:212
logger.info(f"Raw token received: {token[:50]}...{token[-50:] if len(token) > 100 else ''}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp_http/step10.py:213
logger.info(f"Token length: {len(token)}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp_http/step1.py:25
if not origin or (not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1")):
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp_http/step10.py:78
"http://127.0.0.1",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp_http/step10.py:80
"http://127.0.0.1:9000",
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp_http/step10.py:185
if not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1"):
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/mcp_http/step2.py:34
if not origin or (not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1")):
LOWInventory / provenance · inv.hidden_file · CWE-1104
.cursorignore
.cursorignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
agentgateway/config.yaml:1
# yaml-language-server: $schema=../../schema/local.json
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:214
```bash# Get token for admin user (full access)
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:215
curl -X POST "http://localhost:8080/realms/mcp-realm/protocol/openid-connect/token" \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: critical_finding, no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 6658b52abdb2full audit observations/trust-audit/mcp-server/christian-posta__auth-step-by-step.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076658b52abdb2BLOCKF56first audit
06

Questions

What is the Auth Step-by-Step MCP server?

Step by step walkthrough of an MCP Authorization implementation

What tools does Auth Step-by-Step expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Auth Step-by-Step safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Auth Step-by-Step need?

It reads KEYCLOAK_REALM and KEYCLOAK_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (6658b52abdb2), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement