MCP 서버

tollbooth-oauth2-collector

io.github.lonniev/tollbooth-oauth2-collector
MCP 및 에이전트 인프라 보안 공개 · 연결 가능 MCP 2025-11-25

이 MCP로 할 수 있는 일

Stores and retrieves sealed OAuth2 authorization codes for Tollbooth MCP services and exposes collector health and deployment status.

collector_status
Health check — shows the number of pending authorization codes and TTL.
입력 스키마
{'type': 'object', 'properties': {}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'additionalProperties': True}
retrieve_code
Retrieve a stored authorization code (one-time read, auto-deleted). Called by the originating MCP server to pick up the code after the user has authorized in the browser. Returns the encrypted code which the caller decrypts using the same state token.
입력 스키마
{'type': 'object', 'required': ['state'], 'properties': {'state': {'type': 'string', 'description': 'The state token (patron npub) used during authorization.'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'additionalProperties': True}
service_status
Report the running build so a redeploy can be verified. Free. Delegates to the SDK's canonical ``build_service_status`` — the single source of the service_status payload shape — so this collector reports the same envelope as every other DPYC service. The load-bearing field is ``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually deployed. The post-merge deploy-verify probe reads it to confirm the live service redeployed the merged sha; with no ``service_status`` tool to probe, that sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as "did not land". The vault/courier/operator fields are ``False``/empty by construction — this is an unauthenticated community utility with no operator runtime.
입력 스키마
{'type': 'object', 'properties': {}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'additionalProperties': True}
store_code
Store a sealed OAuth2 authorization code. Called by the serverless callback function after the browser redirect. The ``state`` carries BOTH the patron npub (the lookup/retrieve key) and the operator npub (the PUBLIC key the code is sealed to) — see the SDK's ``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only that operator's nsec can open it; the Neon row is keyed by the patron npub, so retrieval (``retrieve_code(state=patron_npub)``) is unchanged.
입력 스키마
{'type': 'object', 'required': ['code', 'state'], 'properties': {'code': {'type': 'string', 'description': 'The authorization code from the OAuth provider.'}, 'state': {'type': 'string', 'description': 'The packed state (``patron_npub.operator_npub``).'}}, 'additionalProperties': False}
출력 스키마
{'type': 'object', 'additionalProperties': True}
추가됨
service_status
2026년 9월 17일 12:43 PM
추가됨
collector_status
2026년 9월 17일 12:43 PM
추가됨
retrieve_code
2026년 9월 17일 12:43 PM
추가됨
store_code
2026년 9월 17일 12:43 PM