MCP OAuth & Authorization Contract Preflight
Validate supplied MCP OAuth metadata and transcripts for discovery, audience, scopes, PKCE, challenges, and token hazards.
What problem does MCP OAuth & Authorization Contract Preflight solve?
MCP server and client teams debug 401 challenges, protected-resource metadata, issuer discovery, resource indicators, PKCE, scopes, and token audience from ad hoc traces.
Use it to
- Preflight an MCP 401 discovery exchange
- Check PKCE and resource-indicator evidence
- Block token passthrough and wrong-audience acceptance evidence
What it returns
- findings.csv with stable codes and evidence sources
- review-manifest.csv with every reviewed record
- result.json with READY, REVIEW, or BLOCK gate and SHA-256 receipt
- report.md with a human-review handoff
A representative input and result
Access and approval boundaries
- Terminal permission to run the bundled local Python reconciler.
- Read access to one user-selected normalized UTF-8 JSON packet.
- Write access only to one user-selected local output directory.
- No browser, network, credential, account, environment-variable, messaging, payment, deletion, access-change, filing, or publication permission.
Known limitations
- The fixed rule snapshot can become stale and must be reviewed against the current MCP specification.
- The package does not send OAuth requests, handle tokens, or prove server interoperability.
- READY is not authorization to deploy or a security certification.
Questions
Does it connect to a live account or provider?
No. It reads one normalized local JSON packet and makes no network request.
Does it make the final decision or external change?
No. It produces evidence findings; the responsible owner makes every decision and action outside the package.
Is the result deterministic?
Yes. Stable finding codes, sorted records, and a SHA-256 receipt make repeated review inspectable.
What happens with malformed input?
Unreadable JSON, missing arrays, duplicate core identifiers, invalid timestamps, and invalid core numbers fail closed.
Does READY prove the underlying evidence is true?
No. READY means no automated finding appeared in the supplied normalized packet; source truth still requires human review.
MCP OAuth & Authorization Contract Preflight keeps proof and approval boundaries visible.
The listing includes the tested package, realistic samples, declared permissions, and known limitations.
Get MCP OAuth & Authorization Contract Preflight on Agensi