{"repo":"workos/pipes-mcp","free":true,"listed":false,"github":"https://github.com/workos/pipes-mcp","clone":"git clone https://github.com/workos/pipes-mcp.git","description":"A sample MCP server with human-approved, provider-scoped access to third-party APIs using WorkOS Pipes.","language":"TypeScript","stars":29,"topics":[],"license":"MIT","category":"mcp-servers","readme_excerpt":"Pipes MCP Template A starter template for building an MCP server with human-approved, provider-scoped access to third-party APIs using WorkOS Pipes. It shows one way to let AI assistants securely interact with services like Linear, Notion, Snowflake, and more with a human in the loop, without trying to prescribe the full deployment story or how approval requests should be delivered. What's included - Human-in-the-loop approval flow — AI assistants request access, humans approve via a browser-based consent screen - Provider-scoped authority — humans select exactly which integrations to authorize (not all-or-nothing) - Unified authority grants — broad and per-request approvals share one AuthorityGrant model - Time-limited sessions — authority expires after 5 minutes, configurable - Read/write gating — read and write operations are gated separately - Approval polling — assistants poll for results and receive user instructions The approval flow Broad authority and per-request approval now use the same underlying grant record: - kind: \"broad\" grants temporary session authority for selected providers - kind: \"request\" approves one exact API call and is consumed on execution Authorization structure Every MCP request is authenticated first, then authorized from the current Pipes session and grant state: 1. app/[transport]/route.ts requires AuthKit authentication for every MCP request. 2. lib/mcp/with-authkit.ts verifies the bearer token, loads the WorkOS user, and loads or creates a ","default_branch":null,"files":null,"tree":[],"storefront":"/r/workos","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/workos/pipes-mcp/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}