Skip to main content

Installation

Published release: @grantex/mcp-auth@4.1.0. Its npm archive matches the validated CI artifact. The earlier 4.0 consumer-flow evidence remains historical. Deployment profile: @grantex/mcp-auth@4.1.0; confirm publication in release status. Node.js 22.12+ and SDK 0.8.1+ are required; Node.js 24 LTS is recommended.
Read release validation and the breaking migration guide before upgrading.

Authorization and deployment

Version 4 supplies OAuth 2.1 endpoints, PKCE S256, protected-resource metadata, resource/audience binding, rendered consent, single-use codes, refresh rotation and explicit token revocation configuration. The complete deployment guide contains executable storage, consent, middleware, lifecycle-hook and decision-grant examples.
  1. Pin the canonical HTTPS issuer and protected resource.
  2. Provision shared Postgres or Redis state and apply its migrations before scaling.
  3. Supply resolvePrincipal(request) from a verified host session; live Grantex consent still requires a passkey. Approval and callback reject logout or a changed principal.
  4. Connect resource middleware to the authorization server’s revocation storage.
  5. Supply currentGrant: grantexCurrentGrantVerifier(grantex) to check current issuer authority before protected execution. Mark sensitive tools decision-required and consume action-bound human decisions.
  6. Test your client, proxy, storage restart/failure and principal handoff before production.
Memory storage remains evaluation-only. revocations: 'none' is a warned opt-out, not revocation enforcement. Token revocation storage is not every upstream grant-state check: the online verifier is also required. The host owns verified principal login. Independent cross-vendor certification is not claimed. See MCP Auth Server for the request flow and operator responsibilities. The six immutable 2.0.2 limitations remain in the historical guide, not the version 4 deployment profile.
Last modified on October 4, 2026