Lightweight OAuth 2.0 callback handler for Node.js, Deno, and Bun with built-in browser flow and MCP SDK integration
This is a utility library for OAuth callback handling, not a traditional MCP server exposing agent-callable tools. The five exported functions are developer APIs rather than tools meant for LLM invocation. Tool naming is reasonable (verb_noun pattern), but descriptions are inconsistent, some are clear, others lack specificity. Parameter schemas are partially documented; some use complex nested objects without full type clarity. The library is well-engineered for its domain (OAuth handling) but poorly suited as an MCP agent tool set. No error handling guidance for LLM-driven recovery. Security (token storage) is thoughtful but not reflected in tool definitions.
Factory for MCP SDK-compatible OAuth provider using browser flow
Persistent file-based token storage. Serializes mutations within a single store instance. Not safe for concurrent access to the same file across multiple instances or processes. Default: ~/.mcp/tokens.json
Captures OAuth authorization code via localhost callback. Starts a temporary server, optionally launches auth URL, waits for redirect.
Builds the redirect URI for OAuth configuration. Use this to construct the redirect_uri parameter for your authorization URL.
Ephemeral in-memory token storage. Tokens lost on process restart.
Tool naming does not follow verb_noun pattern required for LLM agent discovery. 'browserAuth', 'inMemoryStore', 'fileStore' read as nouns/factories; should be 'configure_browser_auth', 'create_memory_store', 'create_file_store'.
No output schemas documented for any tool. LLMs cannot infer what each function returns or plan downstream calls. Critical for agent integration.
Parameter types incomplete for complex inputs. 'browserAuth' options.store is documented as 'object' but its interface is not defined. 'browserAuth' options.launch is documented as 'function' but its signature (arguments, return type) is not specified.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-21 | D | 58 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 57 | - | v1 |
No error handling guidance. If OAuth flow times out, is cancelled, or receives an error from the provider, what does the tool return? How should an LLM respond? No recovery suggestions.
Descriptions lack dependency and context guidance. 'browserAuth' vs 'getAuthCode', when does an LLM use one vs the other? Missing 'Call X first if you only have Y' patterns.
fileStore documentation warns of concurrency issues but provides no guard mechanisms or guidance on how to avoid data loss. Missing guidance on exclusive file locking or safe multi-process usage.
getAuthCode input schema lists 'string | GetAuthCodeOptions' but string variant behavior ('auto-launches browser') is not formalized in the schema, only described in text. No enum or oneOf constraint.