authserver — security grade SAFE, quality 67/100

Security audit verdict: SAFE · quality 67/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by AuthPlane · MCP Server · ★ 76

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is authserver safe to install? View the security audit →

About authserver

Authplane The self-hosted authorization server for the Model Context Protocol. One Go binary. AGPL-3.0. MCP Authorization spec 2025-11-25, end-to-end. AI coding agents: read AGENTS.md first — it has the deterministic workflow for adding Authplane to an existing MCP server, the SDK pins per stack, and the three byte-for-byte rules that cause 90% of failures. If you're an agent operating from web docs (no clone), llms.txt is the same link map in the llmstxt.org convention. Why Authplane Building an MCP server is now a one-afternoon job. Securing it isn't. You need to issue tokens, validate them, federate to your existing IdP, and let agents act on each other's behalf without losing the user behind the chain. Authplane is the one piece of infrastructure that answers all of that. Spec-compliant access tokens for any MCP server in any language — discovery, scopes, audience binding, refresh ro

apps-sdkauthorizationauthorization-servercibaclaudedpopjwtmcpmcp-authmcp-authorization

Quick Facts

Stars76
Forks5
LanguageGo
CategoryMCP Server
LicenseAGPL-3.0
Quality Score66.623952397054/100
Open Issues1
Last Updated2026-09-22
Created2026-06-11
Platformsclaude-code, go, mcp
Est. Tokens~18k

Compatible Skills

These tools work well together with authserver for enhanced workflows:

  • hasmcp-ce — semantic(0.41)+rare_topics+same_lang+similar_pop+shared_platform (58%)
  • llm-agent-audit — semantic(0.41)+complementary+rare_topics+similar_pop (54%)

authserver alternative? Top 6 similar tools

Looking for a authserver alternative? If you're comparing authserver with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • hasmcp-ce by hasmcp · ⭐ 62

    HasMCP Community Edition

  • Wazuh-MCP-Server by gensecaihq · ⭐ 232

    Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability

  • toolhive-studio by stacklok · ⭐ 167

    ToolHive is an application that allows you to install, manage and run MCP servers and connect them to AI agent

  • gtm-mcp-server by paolobietolini · ⭐ 163

    An MCP server for Google Tag Manager. Connect it to your LLM, authenticate once, and start managing GTM throug

  • ebay-mcp by YosefHayim · ⭐ 158

    Local MCP server that exposes eBay Sell APIs to AI assistants with OAuth, tool gating, and stdio/HTTP transpor

  • mcp-shodan by BurtTheCoder · ⭐ 118

    MCP server for Shodan — search internet-connected devices, IP reconnaissance, DNS lookups, and CVE/CPE vulnera

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is authserver?

authserver is OAuth 2.1 Authorization Server for the Model Context Protocol (MCP). It is categorized as a MCP Server with 76 GitHub stars.

What programming language is authserver written in?

authserver is primarily written in Go. It covers topics such as apps-sdk, authorization, authorization-server.

How do I install or use authserver?

You can find installation instructions and usage details in the authserver GitHub repository at github.com/AuthPlane/authserver. The project has 76 stars and 5 forks, indicating an active community.

What license does authserver use?

authserver is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to authserver?

The top alternatives to authserver on Agent Skills Hub include hasmcp-ce, Wazuh-MCP-Server, toolhive-studio. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools