OAuth 2.1 / RFC 9728 / MCP authorization conformance catalog. Vendor-neutral test cases that the Authplane SDKs (and any third-party MCP auth library) run against to prove protocol compliance.
-
Updated
Aug 31, 2026 - Python
OAuth 2.1 / RFC 9728 / MCP authorization conformance catalog. Vendor-neutral test cases that the Authplane SDKs (and any third-party MCP auth library) run against to prove protocol compliance.
OAuth 2.1 for MCP servers in one Cloudflare Worker. RFC 9728 + 8414 + 7591, PKCE, dynamic client registration, consent UI, multi-tenant. Deploy in 5 minutes.
MCP OAuth2 plugin secures Model Context Protocol (MCP) traffic on AI Gateway using OAuth 2.0 specification for MCP servers
Diagnose OAuth discovery problems on remote MCP servers: the 401 challenge, RFC 9728 protected resource metadata, authorization server metadata, PKCE S256, client registration, token endpoint error format and an optional PKCE login, checked against the MCP 2026-07-28 and 2025-11-25 authorization rules. Read-only CLI, httpx only, pipx or uvx.
Fail your CI when an MCP endpoint serves its tool list without a token. Runtime probe and GitHub Action that also checks RFC 9728 OAuth posture and emits an HMAC-signed receipt of what was observed. Single file, stdlib only.
OAuth 2.0 bearer-token resource server for Rust HTTP services: JWT access-token validation against a JWKS, RFC 9728 protected-resource metadata, RFC 6750 WWW-Authenticate challenges, an optional static API key, and axum integration. Provider-agnostic (Authentik, Authelia, Kanidm) — every difference is config, never a code branch.
Go library implementing RFC 9728 OAuth 2.0 Protected Resource Metadata
Evidence for what autonomous software does. Conformance checking and signed, verifiable records of agent actions.
To associate your repository with the rfc9728 topic, visit your repo's landing page and select "manage topics."