Skip to content

Conversation

@mattzcarey
Copy link
Collaborator

@mattzcarey mattzcarey commented Oct 28, 2025

Example of how to implement recommended security features on an MCP server using GitHub OAuth.

This is applicable for all MCP servers which act as an OAuth server, (to an MCP client like Claude) and also an OAuth client (to an external OAuth server such as GitHub, Google or Cloudflare Access). We call this type of MCP server a proxy server.

See this document on Securing MCP Servers for more info.

@changeset-bot
Copy link

changeset-bot bot commented Oct 28, 2025

⚠️ No Changeset found

Latest commit: 583a98e

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@pkg-pr-new
Copy link

pkg-pr-new bot commented Oct 28, 2025

Open in StackBlitz

npx https://pkg.pr.new/cloudflare/ai/ai-gateway-provider@297
npx https://pkg.pr.new/cloudflare/ai/workers-ai-provider@297

commit: 5d31a5d

@mattzcarey mattzcarey changed the title feat: implement CSRF protection and KV-based state management EXAMPLE: implement recommended security features for MCP Servers Oct 29, 2025
@mattzcarey mattzcarey changed the title EXAMPLE: implement recommended security features for MCP Servers EXAMPLE: Recommended security features for MCP Servers Oct 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant