Back to Home
gazzadownunder icon

MCP-OAuth-Compliance

Verified Safe

by gazzadownunder

Overview

A web-based tool for testing MCP server OAuth compliance with various RFCs (9728, 8414, 7591, 9068, 7519, 7515), OAuth 2.1, and the MCP 2025-11-25 specification.

Installation

Run Command
npx github:gazzadownunder/mcp-oauth-compliance

Security Notes

The project is a compliance tester, which inherently requires some flexibility regarding security checks (e.g., allowing self-signed certificates by default for testing). This behavior is well-documented, generates warnings, and can be overridden for strict enforcement. There are no indications of 'eval', obfuscation, hardcoded secrets (user-provided secrets are expected for the systems being tested), or other malicious patterns. Network risks related to HTTP connections to non-localhost servers are mitigated by requiring an explicit configuration option ('allowHttpMcpConnection'). Overall, it appears safe for its intended purpose of testing compliance.

Similar Servers

Stats

Interest Score35
Security Score9
Cost ClassLow
Stars4
Forks1
Last Update2026-01-13

Tags

MCPOAuthCompliance TestingDeveloper ToolSecurity