/** * MCP OAuth Provider * * Implementation of the MCP SDK's OAuthClientProvider interface. * Handles OAuth client registration, token storage, and authorization redirection. */ import type { OAuthClientProvider } from "@modelcontextprotocol/sdk/client/auth.js"; import type { OAuthClientMetadata, OAuthTokens, OAuthClientInformation, OAuthClientInformationFull } from "@modelcontextprotocol/sdk/shared/auth.js"; declare const DEFAULT_OAUTH_CALLBACK_PORT = 19876; declare const OAUTH_CALLBACK_PATH = "/callback"; export declare function getConfiguredOAuthCallbackPort(): number; export declare function getOAuthCallbackPort(): number; export declare function setOAuthCallbackPort(port: number): void; /** Configuration options for OAuth */ export interface McpOAuthConfig { grantType?: "authorization_code" | "client_credentials"; clientId?: string; clientSecret?: string; scope?: string; redirectUri?: string; } /** Callbacks for OAuth flow interactions */ export interface McpOAuthCallbacks { onRedirect: (url: URL) => void | Promise; } /** * OAuth provider implementation for MCP servers. * Implements the OAuthClientProvider interface from the MCP SDK. */ export declare class McpOAuthProvider implements OAuthClientProvider { private serverName; private serverUrl; private config; private callbacks; constructor(serverName: string, serverUrl: string, config: McpOAuthConfig, callbacks: McpOAuthCallbacks); private get usesClientCredentials(); /** * The redirect URL for OAuth callbacks. * Uses configured redirectUri if provided, otherwise falls back to default. */ get redirectUrl(): string | undefined; /** * Client metadata for dynamic registration. * Describes this client to the OAuth authorization server. */ get clientMetadata(): OAuthClientMetadata; /** * Get client information (for pre-registered or dynamically registered clients). * Returns undefined if no client info exists or if the server URL has changed. */ clientInformation(): Promise; /** * Save client information from dynamic registration. */ saveClientInformation(info: OAuthClientInformationFull): Promise; /** * Get stored OAuth tokens. * Returns undefined if no tokens exist or if the server URL has changed. */ tokens(): Promise; /** * Save OAuth tokens. */ saveTokens(tokens: OAuthTokens): Promise; /** * Redirect the user to the authorization URL. * This opens the browser for the user to authenticate. * * Throws UnauthorizedError when called outside of a user-initiated flow * (no oauthState saved by startAuth). That path is reached when the SDK * falls through from a failed refresh into a fresh authorization_code * flow, which library hosts cannot complete in-process. */ redirectToAuthorization(authorizationUrl: URL): Promise; /** * Save the PKCE code verifier. */ saveCodeVerifier(codeVerifier: string): Promise; /** * Get the stored PKCE code verifier. * @throws Error if no code verifier is stored */ codeVerifier(): Promise; /** * Save the OAuth state parameter for CSRF protection. */ saveState(state: string): Promise; /** * Get the stored OAuth state parameter. * @throws UnauthorizedError if no flow is in progress (see redirectToAuthorization) */ state(): Promise; /** * Invalidate credentials when authentication fails. * Clears tokens, client info, or all credentials based on the type. */ invalidateCredentials(type: "all" | "client" | "tokens"): Promise; prepareTokenRequest(scope?: string): URLSearchParams | undefined; } export { DEFAULT_OAUTH_CALLBACK_PORT, OAUTH_CALLBACK_PATH }; //# sourceMappingURL=mcp-oauth-provider.d.ts.map