Auth Step-by-StepBLOCK
Step by step walkthrough of an MCP Authorization implementation
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This repository demonstrates building an MCP (Model Context Protocol) server with HTTP transport and JWT authentication, progressing through iterative steps.
This repo is a companion to the in-depth, step-by-step blog posts on "MCP Authorization". See the following:
- Understanding MCP Authorization, Step by Step, Part One
- Understanding MCP Authorization, Step by Step, Part Two
- Understanding MCP Authorization, Step by Step, Part Three
Part 4 (late addition to the series): MCP Authorization With Dynamic Client Registration
MCP Authorization Specification Requirements
The table below shows support for OAuth RFCs required by the MCP authorization specification across major identity providers.
RFC Requirements Summary:
- PKCE: Proof Key for Code Exchange (OAuth 2.1 requirement)
- RFC 8414: OAuth 2.0 Authorization Server Metadata
- RFC 7591: OAuth 2.0 Dynamic Client Registration Protocol
- RFC 8707: Resource Indicators for OAuth 2.0
Overview
The project shows how to build a secure MCP server with:
- FastAPI-based HTTP transport
- JWT token authentication
- OAuth 2.0 metadata endpoints
- Scope-based authorization
- Role-based access control
6658b52abdb2OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-http --env KEYCLOAK_REALM=${KEYCLOAK_REALM} --env KEYCLOAK_URL=${KEYCLOAK_URL} -- uvx mcp-http{
"mcpServers": {
"mcp-http": {
"command": "uvx",
"args": [
"mcp-http"
],
"env": {
"KEYCLOAK_REALM": "${KEYCLOAK_REALM}",
"KEYCLOAK_URL": "${KEYCLOAK_URL}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
echo | read | Echo a message |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (12 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (16)
-----BEGIN PRIVATE KEY-----
print(f"🎫 Token: {token_info['token']}")print(f"🎫 Token: {token}")print(f" - Client secret: {secret}")logger.info(f"Raw token received: {token[:50]}...{token[-50:] if len(token) > 100 else ''}")logger.info(f"Token length: {len(token)}")if not origin or (not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1")):"http://127.0.0.1",
"http://127.0.0.1:9000",
if not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1"):if not origin or (not origin.startswith("http://localhost") and not origin.startswith("http://127.0.0.1")):.cursorignore
# yaml-language-server: $schema=../../schema/local.json
```bash# Get token for admin user (full access)
curl -X POST "http://localhost:8080/realms/mcp-realm/protocol/openid-connect/token" \
Gates applied: critical_finding, no_behavioural_pass, no_license.
6658b52abdb2full audit observations/trust-audit/mcp-server/christian-posta__auth-step-by-step.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 6658b52abdb2 | BLOCK | F | 56 | first audit |
Questions
What is the Auth Step-by-Step MCP server?
Step by step walkthrough of an MCP Authorization implementation
What tools does Auth Step-by-Step expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Auth Step-by-Step safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Auth Step-by-Step need?
It reads KEYCLOAK_REALM and KEYCLOAK_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (6658b52abdb2), read on 2026-10-07. The repository is watched and re-audited when it changes.