UNPKG

@tanstack/ai-mcp

Version:

Host-side Model Context Protocol client for TanStack AI: discover and run MCP server tools, resources, and prompts in any adapter's chat() loop, with generated end-to-end types.

86 lines (85 loc) • 3.3 kB
import { OAuthTokenVerifier } from '@modelcontextprotocol/server'; /** * Options for {@link jwtVerifier}. * `issuer` and `audience` are required. A token for another issuer or * another API must not call this server. */ export type JwtVerifierOptions = { /** The JWKS URL of the authorization server. */ jwksUrl: string; /** The `iss` claim the token must carry. */ issuer: string; /** The `aud` claim the token must carry. Usually this MCP server URL. */ audience: string; /** Accepted JWS algorithms. The default accepts what the key set advertises. */ algorithms?: Array<string>; /** Fetch for the JWKS request. The default is the global `fetch`. */ fetch?: (url: string, init?: RequestInit) => Promise<Response>; }; /** * Options for {@link introspectionVerifier}. * The server sends the token to `introspectionUrl` with HTTP Basic auth. */ export type IntrospectionVerifierOptions = { /** The RFC 7662 introspection endpoint of the authorization server. */ introspectionUrl: string; /** The client id this MCP server uses at the authorization server. */ clientId: string; /** The client secret for `clientId`. */ clientSecret: string; /** Fetch for the introspection request. The default is the global `fetch`. */ fetch?: (url: string, init?: RequestInit) => Promise<Response>; }; /** * Builds an `OAuthTokenVerifier` for a JWT access token. * * The verifier reads the keys from `jwksUrl`, caches them, and checks the * signature, `iss`, `aud`, `exp`, and `nbf` with `jose`. * A token that fails any check gets a 401 from `createMCPServer`. * When the key set cannot be read, the caller gets a 500 `server_error`, * so a provider outage does not look like a bad token. * * `clientId` on the result is the `client_id`, `azp`, or `sub` claim. * `scopes` comes from the `scope` claim. `extra` holds every claim, * so a tool can read `ctx.context.authInfo.extra.sub`. * * @param options - The JWKS URL, the issuer, and the audience * * @example * ```ts * const server = createMCPServer({ * name: 'notes', * version: '1.0.0', * auth: { * verifier: jwtVerifier({ * jwksUrl: 'https://auth.example.com/.well-known/jwks.json', * issuer: 'https://auth.example.com/', * audience: 'https://mcp.example.com/mcp', * }), * }, * }) * ``` */ export declare function jwtVerifier(options: JwtVerifierOptions): OAuthTokenVerifier; /** * Builds an `OAuthTokenVerifier` for an opaque access token. * * The verifier posts the token to the RFC 7662 introspection endpoint. * A token that is not `active` gets a 401 from `createMCPServer`. * When the endpoint fails, the caller gets a 500 `server_error`. * * `clientId`, `scopes`, `expiresAt`, and `extra` come from the * introspection response, the same as {@link jwtVerifier}. * * @param options - The introspection URL and the client credentials * * @example * ```ts * const verifier = introspectionVerifier({ * introspectionUrl: 'https://auth.example.com/oauth/introspect', * clientId: process.env.OAUTH_CLIENT_ID ?? '', * clientSecret: process.env.OAUTH_CLIENT_SECRET ?? '', * }) * ``` */ export declare function introspectionVerifier(options: IntrospectionVerifierOptions): OAuthTokenVerifier;