{"repo":"tuannvm/oauth-mcp-proxy","free":true,"listed":false,"github":"https://github.com/tuannvm/oauth-mcp-proxy","clone":"git clone https://github.com/tuannvm/oauth-mcp-proxy.git","description":"OAuth 2.1 authentication library for Go MCP servers","language":"Go","stars":33,"topics":["authentication","authorization","claude","codex","mcp","oauth","go-sdk","mcp-go"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"OAuth MCP proxy OAuth 2.1 authentication library for Go MCP servers. Supports both MCP SDKs: - ✅ mark3labs/mcp-go - ✅ modelcontextprotocol/go-sdk (official) One-time setup: Configure provider + add WithOAuth() to your server. Result: All tools automatically protected with token validation and caching. mark3labs/mcp-go Official SDK --- Why Use This Library? - Dual SDK support - Works with both mark3labs and official SDKs - Simple integration - One WithOAuth() call protects all tools - Automatic 401 handling - RFC 6750 compliant error responses with OAuth discovery - Zero per-tool config - All tools automatically protected - Fast token caching - 5-min cache with JWT expiry awareness - Security hardened - State replay protection, DoS prevention, input validation - Built-in rate limiting - Token-based rate limiter included - CORS support - OPTIONS pass-through for browser clients - Multiple providers - HMAC, Okta, Google, Azure AD --- How It Works Request Flow Token Validation Flow What oauth-mcp-proxy does: 1. Extracts Bearer tokens from HTTP requests 2. Validates against your OAuth provider (with caching) 3. Adds authenticated user to request context 4. All your tools automatically protected --- 🔒 Security Features Production-ready security hardening built-in: State Replay Protection - Timestamp + nonce validation - States include timestamp and nonce for replay attack prevention - Automatic nonce cleanup - Expired nonces removed before replay check (prevents memory leaks) - Ro","default_branch":null,"files":null,"tree":[],"storefront":"/r/tuannvm","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/tuannvm/oauth-mcp-proxy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}