tollbooth-oauth2-collector

Unauthenticated OAuth2 callback collector for Tollbooth MCP services

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
65%
命名品質
85%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~598Token(工具定義)
~566 B典型回應大小
極小的注意力影響(128k 上下文的 0.47%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "tollbooth-oauth2-collector": {
      "url": "https://tollbooth-oauth2-collector.fastmcp.app/mcp"
    }
  }
}

遠端端點

https://tollbooth-oauth2-collector.fastmcp.app/mcpstreamable-http

它能做什麼

工具清單

工具(4)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪store_code(code, state)

Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.

輸入結構描述

{
  "type": "object",
  "properties": {
    "code": {
      "type": "string",
      "description": "The authorization code from the OAuth provider."
    },
    "state": {
      "type": "string",
      "description": "The packed state (``patron_npub.operator_npub``)."
    }
  },
  "required": [
    "code",
    "state"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢retrieve_code(state)

Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.

輸入結構描述

{
  "type": "object",
  "properties": {
    "state": {
      "type": "string",
      "description": "The state token (patron npub) used during authorization."
    }
  },
  "required": [
    "state"
  ],
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟢collector_status

Health check — shows the number of pending authorization codes and TTL.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}
🟡service_status

Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.

輸入結構描述

{
  "type": "object",
  "properties": {},
  "additionalProperties": false
}

輸出結構描述

{
  "type": "object",
  "additionalProperties": true
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本4 個工具
已驗證未記錄版本4 個工具
已驗證未記錄版本4 個工具