10 packages matching “rfc9728”
@xpaysh/storefront-audit
v0.1.1 · 2 months ago
Conformance + readiness auditor for agentic-commerce storefronts. Checks /llms.txt, /.well-known/ucp, schema.org JSON-LD on PDPs, robots.txt AI-crawler allowlist, A2A agent-card, RFC 9728 OAuth resource metadata, and rejects fictitious well-known URIs. Li
No known vulnerabilities
within-mcp-auth
v0.1.0 · 3 months ago
With.in MCP Auth SDK — validates With.in tokens alongside a vendor's own auth, handles quota, usage reporting, subscriber detection, and cross-vendor network discovery.
No known vulnerabilities
@better-auth/mcp
v1.7.1 · 4 days ago
Model Context Protocol (MCP) plugin for Better Auth
No known vulnerabilities
@xpaysh/lint-wellknowns
v0.1.0 · 3 months ago
CI linter that fails the build when a plugin emits a fictitious well-known URI or agent-discovery file (no spec, no RFC, no IANA registration). Enforces the real-standards-only design principle of the agentic-commerce-for-* plugin family. Run `npx lint-we
No known vulnerabilities
@xpaysh/discovery
v0.1.0 · 3 months ago
Pure-function generators for the real agent-readable discovery surface: /llms.txt (llmstxt.org), schema.org JSON-LD (Product, ItemList), robots.txt allowlist for real AI crawlers, /.well-known/agent-card.json (A2A 1.0), /.well-known/oauth-protected-resour
No known vulnerabilities
@mcpcomp/core
v0.10.0 · 1 day ago
MCP authentication conformance probe engine
No known vulnerabilities
mcp-sso
v0.4.0 · 2 days ago
OAuth 2.1 and enterprise SSO for remote MCP servers—without API keys in client configs.
No known vulnerabilities
mcp-oauth-compliance
v0.2.1 · 7 months ago
Web-based tool for testing MCP server OAuth compliance with RFC 9728, RFC 8414, RFC 7591, and OAuth 2.1
No known vulnerabilities
mcp-authcheck
v0.1.1 · 1 month ago
Grade any MCP server against the MCP authorization spec (OAuth 2.1, RFC 9728/8414/8707). Read-only, non-destructive conformance checks.
No known vulnerabilities
@getonlane/mcp-auth
v0.1.2 · 1 day ago
Drop-in OAuth resource-server + connection gate for an MCP server fronted by Lane. Transport-agnostic core; adapters wrap it.
No known vulnerabilities