tollbooth-oauth2-collector

Unauthenticated OAuth2 callback collector for Tollbooth MCP services

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
100%
Integridad del esquema
65%
Calidad de los nombres
85%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~598Tokens (definiciones de herramientas)
~566 BTamaño de respuesta típico
Impacto mínimo en la atención (0.47% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "tollbooth-oauth2-collector": {
      "url": "https://tollbooth-oauth2-collector.fastmcp.app/mcp"
    }
  }
}

Puntos de conexión remotos

https://tollbooth-oauth2-collector.fastmcp.app/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (4)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
⚪store_code(code, state)

Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The authorization code from the OAuth provider."
    },
    "state": {
      "type": "string",
      "description": "The packed state (``patron_npub.operator_npub``)."
    }
  },
  "required": [
    "code",
    "state"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "additionalProperties": true
}
🟢retrieve_code(state)

Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "The state token (patron npub) used during authorization."
    }
  },
  "required": [
    "state"
  ],
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "additionalProperties": true
}
🟢collector_status

Health check — shows the number of pending authorization codes and TTL.

Esquema de entrada

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "additionalProperties": true
}
🟡service_status

Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.

Esquema de entrada

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "additionalProperties": true
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada4 herramientas
verificadoversión no registrada4 herramientas
verificadoversión no registrada4 herramientas