{"repo":"empires-security/mcp-oauth2-aws-cognito","free":true,"listed":false,"github":"https://github.com/empires-security/mcp-oauth2-aws-cognito","clone":"git clone https://github.com/empires-security/mcp-oauth2-aws-cognito.git","description":"MCP Server Authorization Example with AWS Cognito","language":"JavaScript","stars":68,"topics":["aws","cognito","mcp","oauth2"],"license":"MIT","category":"mcp-servers","readme_excerpt":"MCP + OAuth2.1 + AWS Cognito Example Overview This repository demonstrates how to secure a Model Context Protocol (MCP) server using OAuth 2.1 authorization flows, implemented entirely with Node.js and Express.js. While this example uses AWS Cognito as the backing authorization server, the implementation is provider-agnostic and can work with any OAuth 2.1 compliant authorization server. Based on the MCP Authorization Specification (version 2025-11-25), this project showcases: - MCP server acting as a Resource Server (RS) with generic OAuth endpoints - Provider-agnostic OAuth 2.1 implementation (example uses AWS Cognito) - OAuth 2.1 Authorization Code Flow with PKCE and RFC 8707 Resource Indicators - Protected Resource Metadata (PRM) document discovery - Fully dynamic authorization server metadata discovery - Dynamic Client Registration (DCR) support - Client ID Metadata Documents (CIMD) support - Enhanced security features from MCP 2025-11-25 specification - Three client implementations: - Static client with pre-configured credentials - Auto-discovery client with dynamic registration (DCR) - Metadata client using Client ID Metadata Documents (CIMD) Provider-Agnostic Design This implementation follows OAuth 2.1 standards to ensure compatibility with any compliant authorization server: - MCP Server : Exposes standard OAuth metadata endpoints and proxies to the backing authorization server - Clients : Discover authorization servers dynamically without hardcoded provider-specifi","default_branch":null,"files":null,"tree":[],"storefront":"/r/empires-security","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/empires-security/mcp-oauth2-aws-cognito/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}