- tool schemas0
- tool arguments0
- responses0
- audit rows0
The broker hands out clients, not credentials.
An MCP server that exposes internal databases and APIs to frontier models through delegated OAuth 2.1 with mandatory PKCE. Tool discovery is filtered by grants, credentials stay with a server-side broker, and every call is written to an append-only audit trail.
last 24 h · tenant demo-internal
The broker hands out clients, not credentials.
One session per subject. A revoked grant sends list_changed right away.
Token verify plus RBAC decision.
Hover or focus a layer to open it.
Authorization code flow with mandatory PKCE, EdDSA-signed JWTs, rotating refresh tokens, discovery metadata and JWKS.
RFC 9728 protected-resource metadata, a correct WWW-Authenticate challenge, and a two-part decision: the token scope and the role grant must both allow the tool.
A model only sees the tools its subject is granted. When a grant changes, connected sessions get list_changed live.
Mints short-lived upstream access and returns a client. Named queries come from an allowlist; the model never writes SQL.
One redacted row per invocation, allow or deny. Append-only is enforced by triggers in the database, not by convention.
Checked by a property test over every registered tool definition.
src/server/credentials/It points the client to the protected-resource metadata, so it can discover the authorization server on its own.
src/server/auth/gate/Discovery and invocation run the same policy function, so the two can't disagree.
src/server/tools/Proven through the UI: a revoked call still shows up, with its payload redacted.
src/server/audit/8 tools · 2 upstreams · 4 roles
| Tool | Scope | Upstream | Granted to | Calls 24h | Deny |
|---|---|---|---|---|---|
| customer.lookup | read:customers | legacy_db | analystsupportadmin | 6,212 | 0.4% |
| invoice.search | read:billing | legacy_db | analystadmin | 4,907 | 1.1% |
| ticket.create | write:support | internal_api | supportadmin | 2,318 | 3.9% |
| ticket.update_status | write:support | internal_api | support | 1,776 | 2.2% |
| invoice.summary | read:billing | legacy_db | analystfinance | 2,991 | 0.2% |
{
"mcpServers": {
"internal-tools": {
"url": "https://gateway.local/mcp",
"auth": "oauth"
}
}
}