No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by mcp-auth · MCP Server · ★ 51
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is js safe to install? View the security audit →
MCP Auth Node.js SDK The MCP spec requires OAuth 2.1 and other RFCs for auth. Instead of spending weeks on them, use MCP Auth to connect to a trusted provider with a few lines of code. mcp-auth targets the latest MCP specification and the MCP TypeScript SDK v2, implementing the spec's authorization requirements — RFC 9728 Protected Resource Metadata and RFC 8707 audience-bound token validation — for any OAuth 2.0 / OpenID Connect provider. Get started Is my provider supported? Check out the MCP-compatible providers to see which providers are supported. It also includes a tool for real-time checking of provider compatibility. Installation Or use your package manager of choice, such as or . Still on MCP SDK v1 (@model
| Stars | 51 |
| Forks | 4 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 61.015837070893/100 |
| Last Updated | 2026-08-31 |
| Created | 2025-04-19 |
| Platforms | mcp, node |
| Est. Tokens | ~14k |
These tools work well together with js for enhanced workflows:
Looking for a js alternative? If you're comparing js with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
【Star-crossed coders unite!⭐️】Model Context Protocol (MCP) server implementation providing Google News search
Authentication, analytics, and prompt visibility for MCP servers with zero code changes. Supports OAuth2.1, DC
Absurdly easy Model Context Protocol Servers in Typescript
MCP server for reusable prompt templates, multi-step workflow chains, and quality gates — compose agentic work
📜 An MCP server for conversation history search and retrieval in Claude Code
MCP Auth Proxy is a secure OAuth 2.1 authentication proxy for Model Context Protocol (MCP) servers
Explore other popular mcp server tools:
js is 🔐 Plug-and-play auth for Node.js MCP servers.. It is categorized as a MCP Server with 51 GitHub stars.
js is primarily written in TypeScript. It covers topics such as authentication, authorization, mcp.
You can find installation instructions and usage details in the js GitHub repository at github.com/mcp-auth/js. The project has 51 stars and 4 forks, indicating an active community.
js is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to js on Agent Skills Hub include server-google-news, jetski, easy-mcp. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: