tollbooth-oauth2-collector

Unauthenticated OAuth2 callback collector for Tollbooth MCP services

我该使用它吗

质量与安全性

A
描述质量
100%
模式完整度
65%
命名质量
85%
投毒风险
100%
权限匹配度
100%
协议合规性
100%

基于对工具定义和协议合规性的自动分析。

上下文开销

~598token 数(工具定义)
~566 B典型响应大小
对注意力的影响极小(占 128k 上下文窗口的 0.47%)

这是每次将服务器的工具加载到模型上下文窗口时所消耗的大致 token 数。数值越高,可用于其他任务的注意力就越少。

安装

一键安装

将以下内容添加到你的 `claude_desktop_config.json` 文件中:

{
  "mcpServers": {
    "tollbooth-oauth2-collector": {
      "url": "https://tollbooth-oauth2-collector.fastmcp.app/mcp"
    }
  }
}

远程端点

https://tollbooth-oauth2-collector.fastmcp.app/mcpstreamable-http

它能做什么

工具清单

工具(4)

🟢 只读🟡 写入🔴 删除⚪ 未知
⚪store_code(code, state)

Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.

输入模式

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The authorization code from the OAuth provider."
    },
    "state": {
      "type": "string",
      "description": "The packed state (``patron_npub.operator_npub``)."
    }
  },
  "required": [
    "code",
    "state"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟢retrieve_code(state)

Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.

输入模式

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "The state token (patron npub) used during authorization."
    }
  },
  "required": [
    "state"
  ],
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟢collector_status

Health check — shows the number of pending authorization codes and TTL.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}
🟡service_status

Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.

输入模式

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

输出模式

{
  "type": "object",
  "additionalProperties": true
}

社区

评价此服务器

证据

最近观测

已验证未记录版本4 个工具
已验证未记录版本4 个工具
已验证未记录版本4 个工具