Installation
Published release: @grantex/mcp-auth@4.1.0. Its npm archive matches the
validated CI artifact. The earlier 4.0 consumer-flow evidence remains historical.
Deployment profile: @grantex/mcp-auth@4.1.0; confirm publication in
release status. Node.js 22.12+ and SDK 0.8.1+
are required; Node.js 24 LTS is recommended.
Read release validation and the
breaking migration guide before upgrading.
Authorization and deployment
Version 4 supplies OAuth 2.1 endpoints, PKCE S256, protected-resource
metadata, resource/audience binding, rendered consent, single-use codes,
refresh rotation and explicit token revocation configuration. The
complete deployment guide contains executable storage,
consent, middleware, lifecycle-hook and decision-grant examples.
- Pin the canonical HTTPS issuer and protected resource.
- Provision shared Postgres or Redis state and apply its migrations before scaling.
- Supply
resolvePrincipal(request) from a verified host session; live Grantex consent still requires a passkey. Approval and callback reject logout or a changed principal.
- Connect resource middleware to the authorization server’s revocation storage.
- Supply
currentGrant: grantexCurrentGrantVerifier(grantex) to check current issuer authority before protected execution. Mark sensitive tools decision-required and consume action-bound human decisions.
- Test your client, proxy, storage restart/failure and principal handoff before production.
Memory storage remains evaluation-only. revocations: 'none' is a warned
opt-out, not revocation enforcement. Token revocation storage is not every
upstream grant-state check: the online verifier is also required. The host owns
verified principal login. Independent cross-vendor certification is not claimed.
See MCP Auth Server for the request flow and
operator responsibilities. The six immutable 2.0.2 limitations remain in
the historical guide, not the version 4 deployment profile.Last modified on October 4, 2026