{"repo":"AuthPlane/authserver","free":true,"listed":false,"github":"https://github.com/AuthPlane/authserver","clone":"git clone https://github.com/AuthPlane/authserver.git","description":"OAuth 2.1 Authorization Server for the Model Context Protocol (MCP)","language":"Go","stars":50,"topics":["ciba","mcp","mcp-auth","mcp-authorization","mcp-security","oauth2","oauth21","xaa","authorization","authorization-server"],"license":"AGPL-3.0","category":"auth-billing-email","readme_excerpt":"Authplane The self-hosted authorization server for the Model Context Protocol. One Go binary. AGPL-3.0. MCP Authorization spec 2025-11-25 , end-to-end. AI coding agents: read AGENTS.md first — it has the deterministic workflow for adding Authplane to an existing MCP server, the SDK pins per stack, and the three byte-for-byte rules that cause 90% of invalid token failures. If you're an agent operating from web docs (no clone), llms.txt is the same link map in the llmstxt.org convention. Why Authplane Building an MCP server is now a one-afternoon job. Securing it isn't. You need to issue tokens, validate them, federate to your existing IdP, and let agents act on each other's behalf without losing the user behind the chain. Authplane is the one piece of infrastructure that answers all of that. - Spec-compliant access tokens for any MCP server in any language — discovery, scopes, audience binding, refresh rotation, in token formats your existing resource servers already understand. - Federation to your existing IdP — Google, Okta, Azure AD, Auth0, anyone OIDC-compliant. Authplane handles the OAuth side; you keep the access policy. - Agent-to-agent delegation — one agent calls another on a user's behalf, with every hop recorded as an act-claim chain in the issued token and the audit log. - Upstream provider vaulting — store GitHub / Google / Slack / Linear refresh tokens encrypted at rest and vend fresh access tokens via RFC 8693, with per-user / per-agent / per-resource consent e","default_branch":null,"files":null,"tree":[],"storefront":"/r/AuthPlane","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AuthPlane/authserver/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}