OAuth 2.1 server implementation with MCP (Model Context Protocol) integration, providing OAuth client registration, authorization, token exchange, and MCP tool endpoints with token-based authentication
This MCP server exposes only a single tool (add_numbers) with minimal real-world utility. The tool has a basic description and input schema, but lacks critical production patterns: no error handling guidance, no output schema documentation, no pagination (where applicable), no idempotency guarantees, and no security considerations. The server itself is an OAuth gateway (per the repo name and visible code), but the MCP tool exposed does not reflect that functionality, it appears to be a trivial demo tool. The codebase shows a Next.js/Express-based OAuth implementation with database integration (Drizzle ORM, PostgreSQL), but the MCP layer is superficial. The tool definition exists but the implementation does not meaningfully integrate the OAuth functionality that the server was built for.
Adds two numbers together and returns the sum
Single trivial tool with no production value. Tool 'add_numbers' is a mathematical utility with no connection to the OAuth gateway domain. No evidence of tools that expose OAuth registration, token management, or credential flow operations, the actual server capabilities.
No output schema documented. The tool description states it 'Adds two numbers together and returns the sum' but does not specify the return type (number, object, etc.), structure, or whether there are error cases.
No error handling or recovery guidance. Tool provides no guidance on what happens if inputs are invalid (non-numbers, NaN, Infinity), or how the LLM should recover.
Tool description is generic (46 chars). 'Adds two numbers together and returns the sum' lacks context on WHEN to use this tool, prerequisites, or constraints. Baseline for descriptions is 194 chars average with good context.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 48 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 32 | - | v1 |
Input schema lacks parameter constraints. Parameters 'a' and 'b' are typed as number but lack min/max bounds, range constraints, or handling of edge cases (negative numbers, very large numbers, decimals).
OAuth functionality completely absent from MCP tool set. The server implements OAuth 2.0 registration, token generation, and client management (visible in src/app/api/oauth/register/route.ts, src/app/api/oauth/token/route.ts) but exposes NO MCP tools for these operations. Agents cannot interact with the core server capability.
No tool annotations. Tool lacks idempotentHint, readOnlyHint, or destructiveHint to signal to the LLM whether it is safe to retry, call multiple times, or has side effects.