HTTP OAuthSAFE
Remote MCP server (SEE + Streamable HTTP) implementing the MCP spec's authorization extension. Use directly from your agents, or from Cursor / Claude with mcp-remote
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Introduction
This repo provides a reference implementation for creating a remote MCP server that supports the Streamable HTTP & SSE Transports, authorized with OAuth based on the MCP specification.
Note that the MCP server in this repo is logically separate from the application that handles the report SSE + HTTP transports, and from OAuth.
As a result, you can easily fork this repo, and plug in your own MCP server and OAuth credentials for a working SSE/HTTP + OAuth MCP server with your own functionality.
But, why?
Great question! The MCP specification added the authorization specification based on OAuth on March 25, 2025. At present, as of May 1, 2025:
- The Typescript SDK contains many of the building blocks for accomplishing an OAuth-authorized MCP server with streamable HTTP, but there is no documentation or tutorial on how to build such a server
- The Python SDK contains neither an implementation of the streamable HTTP transport, nor an implementation of the OAuth building blocks that are present in the typescript SDK
- The Streamable HTTP transport is broadly unsupported by MCP host applications such as Cursor and Claude desktop, though it may be integrated directly into agents written in JavaScript using the JS/TS SDK's
StreamableHttpClientTransportclass
At Naptha AI, we really wanted to build an OAuth-authorized MCP server on the streamable HTTP transport, and couldn't find any reference implementations, so we decided to build one ourselves!
Dependencies
Bun, a fast all-in-one JavaScript runtime, is the recommended runtime and package manager for this repository. Limited compatibility testing has been done with npm + tsc.
Overview
This repository provides the following:
- An MCP server, which you can easily replace with your own
- An express.js application that manages both the SSE and Streamable HTTP transports and OAuth authorization.
T
300c522a5152OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add http-oauth-mcp-server --env TOKEN_STORAGE_STRATEGY=${TOKEN_STORAGE_STRATEGY} -- npx -y http-oauth-mcp-server{
"mcpServers": {
"http-oauth-mcp-server": {
"command": "npx",
"args": [
"-y",
"http-oauth-mcp-server"
],
"env": {
"TOKEN_STORAGE_STRATEGY": "${TOKEN_STORAGE_STRATEGY}"
}
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | Add two numbers |
divide | read | Divide two numbers |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
"eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InoxVmx1eHV5Wk5IUHNvbXA0WkxEVCJ9.eyJuaWNrbmFtZSI6IkstTWlzdGVsZSIsIm5hbWUiOiJLeWxlIE1pc3RlbGUiLCJwaWN0dXJlIjoiaHR0cHM6Ly9hdmF0YXJzLmdpdGh1YnVzZXJjb250ZW50Lm
.env.template
@modelcontextprotocol/sdk, dotenv, express, ioredis, jsonwebtoken, jwks-rsa, logging, @types/bun
Gates applied: no_behavioural_pass.
300c522a5152full audit observations/trust-audit/mcp-server/napthaai__http-oauth.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 300c522a5152 | SAFE | B | 89 | first audit |
Questions
What is the HTTP OAuth MCP server?
Remote MCP server (SEE + Streamable HTTP) implementing the MCP spec's authorization extension. Use directly from your agents, or from Cursor / Claude with mcp-remote
What tools does HTTP OAuth expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is HTTP OAuth safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does HTTP OAuth need?
It reads TOKEN_STORAGE_STRATEGY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does HTTP OAuth run?
It speaks sse and streamable-http, so it runs as a service you connect to over the network. It is published on npm as http-oauth-mcp-server.
How current is this page?
The grade is for one exact copy of the source (300c522a5152), read on 2026-10-07. The repository is watched and re-audited when it changes.