Simple MCP Server with upstream auth via local rest endpoint

by BarDweller

312 downloads
Not rated
GitHub

About

This is a prototype MCP server that offers tools but limits their access based on internal state. Users must authenticate via an external URL that uses Quarkus OIDC with GitHub OAuth. The resulting access token is stored per session ID.

Details

Author
BarDweller
Downloads
312
Categories
Developer Tools

- Requires authentication via GitHub OAuth before tool access
- Stores access tokens per session ID for reuse
- Integrates with standard MCP clients like Claude Desktop
- Uses JBang for execution with a Maven artifact
- Leverages Quarkus OIDC for the OAuth flow
- Provides a local REST endpoint for callback (localhost:8080)

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Simple MCP Server with upstream auth via local rest endpoint
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Install JBang and create a GitHub OAuth App with the callback URL set to http://127.0.0.1:8080/auth. Copy the client ID and secret into application.properties. Then configure your MCP client (e.g., Claude Desktop) to run the JBang command jbang --quiet org.ozzy:stiletto:1.0.0-SNAPSHOT:runner. Authentication is initiated when a tool is used without a valid session.

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "simple mcp server with upstream auth via local rest endpoint": {
            "ozzynet": {
                "command": "cmd",
                "args": [
                    "/c",
                    "C:\\Users\\YOURUSERNAME\\.jbang\\bin\\jbang.cmd",
                    "--quiet",
                    "org.ozzy:stiletto:1.0.0-SNAPSHOT:runner"
                ]
            }
        }
    }
}

McpServers

{
    "ozzynet": {
        "command": "cmd",
        "args": [
            "/c",
            "C:\\Users\\YOURUSERNAME\\.jbang\\bin\\jbang.cmd",
            "--quiet",
            "org.ozzy:stiletto:1.0.0-SNAPSHOT:runner"
        ]
    }
}

Simple MCP Server with upstream auth via local rest endpoint

This is a prototype where an MCP server offers tools, but limits their access based on internal state,
requiring the user to authenticate via an external url.

In this case, the external url is wrappered with quarkus oidc, requiring authentication via github

The resulting access token for github is then stored within the mcp for the sessionid used by the user

Note: you must edit application.properties to add your client-id and secret for your GitHub OAuth app.

Requirements

- JBang
- OAuth2 App with GitHub
- MCP Client like claude

Creating an OAuth2 App with GitHub

Navigate to https://github.com/settings/developers

Select OAuth Apps from the left nav

Click 'New OAuth App'

Give it a name, and set the callback url to be http://127.0.0.1:8080/auth

Copy the client ID to application.properties
Click 'generate a new client secret' and copy the secret to application.properties

Update claude desktop config json...

For windows...

{
"mcpServers": {
"ozzynet": {
"command": "cmd",
"args": [
"/c",
"C:\\Users\\YOURUSERNAME\\.jbang\\bin\\jbang.cmd",
"--quiet",
"org.ozzy:stiletto:1.0.0-SNAPSHOT:runner" ]
}
}
}

For mac...

{
"mcpServers": {
"ozzynet": {
"command": "jbang",
"args": [
"--quiet",
"org.ozzy:stiletto:1.0.0-SNAPSHOT:runner" ]
}
}
}

Testing..

Ask claude to list the issues for a repository ..

eg, list the issues for quarkusio's quarkus repo

Claude will ask permission to invoke the getSessionId tool
Claude will then invoke the listIssues tool, and report it cannot use it, because you need to be authenticated, and will offer you
a link of the form http://127.0.0.1/auth?sessionId=<UUID> .. when you click that, you will be redirected to github, to authorize via
the OAuthApp you created. When auth is complete, you can return to claude, and retry the list operation =)

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.