tollbooth-oauth2-collector

Unauthenticated OAuth2 callback collector for Tollbooth MCP services

Sollte ich dies verwenden

Qualität und Sicherheit

A
Qualität der Beschreibung
100%
Vollständigkeit des Schemas
65%
Qualität der Benennung
85%
Risiko der Vergiftung
100%
Übereinstimmung der Berechtigungen
100%
Einhaltung des Protokolls
100%

Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.

Kontextkosten

~598Tokens (Tool-Definitionen)
~566 BTypische Antwortgröße
Minimale Auswirkung auf die Aufmerksamkeit (0.47% von 128k Kontext)

Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.

Installieren

Installation mit einem Klick

Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:

{
  "mcpServers": {
    "tollbooth-oauth2-collector": {
      "url": "https://tollbooth-oauth2-collector.fastmcp.app/mcp"
    }
  }
}

Remote-Endpunkte

https://tollbooth-oauth2-collector.fastmcp.app/mcpstreamable-http

Was es kann

Tool-Inventar

Tools (4)

🟢 Nur lesen🟡 Schreiben🔴 Löschen⚪ Unbekannt
⚪store_code(code, state)

Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The authorization code from the OAuth provider."
    },
    "state": {
      "type": "string",
      "description": "The packed state (``patron_npub.operator_npub``)."
    }
  },
  "required": [
    "code",
    "state"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢retrieve_code(state)

Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.

Eingabe-Schema

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "The state token (patron npub) used during authorization."
    }
  },
  "required": [
    "state"
  ],
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢collector_status

Health check — shows the number of pending authorization codes and TTL.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "additionalProperties": true
}
🟡service_status

Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.

Eingabe-Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Ausgabe-Schema

{
  "type": "object",
  "additionalProperties": true
}

Community

Diesen Server bewerten

Nachweis

Aktuelle Beobachtungen

verifiziertVersion nicht aufgezeichnet4 Tools
verifiziertVersion nicht aufgezeichnet4 Tools
verifiziertVersion nicht aufgezeichnet4 Tools