tollbooth-oauth2-collector

Unauthenticated OAuth2 callback collector for Tollbooth MCP services

Should I use this

Quality & Safety

A
Description quality
100%
Schema completeness
65%
Naming quality
85%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~598Tokens (tool definitions)
~566 BTypical response size
Minimal attention impact (0.47% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "tollbooth-oauth2-collector": {
      "url": "https://tollbooth-oauth2-collector.fastmcp.app/mcp"
    }
  }
}

Remote endpoints

https://tollbooth-oauth2-collector.fastmcp.app/mcpstreamable-http

What it can do

Tool inventory

Tools (4)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
⚪store_code(code, state)

Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.

Input Schema

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The authorization code from the OAuth provider."
    },
    "state": {
      "type": "string",
      "description": "The packed state (``patron_npub.operator_npub``)."
    }
  },
  "required": [
    "code",
    "state"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢retrieve_code(state)

Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.

Input Schema

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "The state token (patron npub) used during authorization."
    }
  },
  "required": [
    "state"
  ],
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟢collector_status

Health check — shows the number of pending authorization codes and TTL.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}
🟡service_status

Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.

Input Schema

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Output Schema

{
  "type": "object",
  "additionalProperties": true
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded4 tools
verifiedversion not recorded4 tools
verifiedversion not recorded4 tools