Skip to content

feat: accept OAuth 2.1 access tokens and sync with the hosted server - #2

Merged
rbatista191 merged 1 commit into
mainfrom
feat/oauth
Sep 29, 2026
Merged

rbatista191 merged 1 commit into
mainfrom
feat/oauth

Conversation

@rbatista191

Copy link
Copy Markdown
Contributor

Summary

Port the hosted server's changes (cloro-dev/backend apps/mcp) since this mirror was published.

  • OAuth 2.1 (backend ENG-882, cloro-dev/backend#336): the server accepts an access token from the Clerk issuer as well as a cloro API key. initialize and tools/list answer without a credential. A tools/call without one returns 401 with a WWW-Authenticate challenge. The protected resource metadata is served at both well-known paths. The token verifier is vendored in src/oauth-tokens/ and adds the jose dependency. OAuth is off unless CLERK_ISSUER is set.
  • Schemas: re-vendored from @repo/api-schemas. The Google tools take gl and hl (country is a deprecated alias), ChatGPT takes legacy, and include.rawHtml no longer exists.
  • Version 0.2.0 in package.json, src/server.ts, server.json and .cursor-plugin/plugin.json. server.json matches cloro-dev/backend#388: repository field, Authorization header optional.
  • README: Claude OAuth setup, the OAuth env vars for self-hosting, gl/hl.
  • tsconfig: add the DOM lib for the CryptoKey and RequestInfo types in the vendored tests.

The hosted deployment's Prometheus metrics stay out of this repo, as before. Two backend tests that assert on those metrics are left out.

Test

  • tsc --noEmit: passes.
  • vitest run: 91 passed.
  • npm run build: passes.

https://claude.ai/code/session_01DBpCib1v2KCNjNijH5ersL

Port the hosted server's changes since this mirror was published.

- OAuth 2.1 (backend ENG-882): the server accepts an access token from
  the Clerk issuer as well as a cloro API key. initialize and tools/list
  answer without a credential. A tools/call without one returns 401 with
  a WWW-Authenticate challenge. The protected resource metadata is served
  at both well-known paths. The token verifier is vendored in
  src/oauth-tokens/ and adds the jose dependency. OAuth is off unless
  CLERK_ISSUER is set.
- Schemas: re-vendor from the backend. The Google tools take gl and hl
  (country is a deprecated alias), ChatGPT takes legacy, and
  include.rawHtml no longer exists.
- Version 0.2.0 in package.json, src/server.ts, server.json and the
  Cursor plugin manifest. server.json gets the repository field and
  makes the Authorization header optional.
- tsconfig: add the DOM lib for the CryptoKey and RequestInfo types in
  the vendored tests.

The hosted deployment's Prometheus metrics stay out of this repo, as
before.

Claude-Session: https://claude.ai/code/session_01DBpCib1v2KCNjNijH5ersL
@rbatista191
rbatista191 merged commit b255858 into main Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant