{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_423jm9jkpyrs","handle":"authsome-mcp-proxy","url":"https://wellknown.network/agents/authsome-mcp-proxy","links":{"self":"https://wellknown.network/agents/authsome-mcp-proxy/record.json","html":"https://wellknown.network/agents/authsome-mcp-proxy","markdown":"https://wellknown.network/agents/authsome-mcp-proxy/record.md","api":"https://wellknown.network/api/v1/agents/authsome-mcp-proxy","status":"https://wellknown.network/api/v1/agents/authsome-mcp-proxy/status","claim":"https://wellknown.network/agents/authsome-mcp-proxy/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/authsome-mcp-proxy/claim.json","badge":"https://wellknown.network/agents/authsome-mcp-proxy/badge.svg","openapi":"https://wellknown.network/openapi.json"},"ard":{"identifier":"urn:air::server:authsome-mcp-proxy","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"authsome-mcp-proxy","summary":"A Model Context Protocol (MCP) proxy that adds an OAuth/OIDC frontend to upstream MCPs that don't include any such — either because they only validate tokens or expect static credentials such as API keys. Bridges to a configurable IdP (Keycloak, AWS Cognito, Google, Azure, generic OIDC) for Claude …","description":"<!-- omit from toc -->\n# Authsome MCP Proxy\n\nA [Model Context Protocol](https://modelcontextprotocol.com) (MCP) proxy that\nbridges *upstream MCP servers protected by token validation or static\ncredentials* to MCP clients such as Claude Desktop, Claude Code, Cursor,\nCodex, MCP Inspector, and Claude.ai. (\"Authsome\" as in *awesome*, but with\nauth.)\n\nThe proxy can run as:\n\n- **Web connector** (`--transport http`, **recommended for end users**) —\n  a persistent HTTP server that any MCP client reaches by URL. Downstream\n  clients authenticate against the proxy via Dynamic Client Registration\n  or a Client ID Metadata Document; the proxy bridges to your IdP and\n  forwards traffic upstream. A single\n  instance can serve many users simultaneously and lives behind a normal\n  URL (`https://mcp.example.com/mcp`) — no per-user config files,\n  subprocess launchers, or local Python toolchains. This is the default\n  for non-developer rollouts and the only mode that works with web-only\n  clients like Claude.ai.\n\n- **Local stdio proxy** (`--transport stdio`, the default for backwards\n  compatibility, **developer use**) — launched as a subprocess by the MCP\n  client (Claude Desktop, Cursor, Codex, Claude Code via `claude mcp\n  add --transport stdio`). Each user runs their own instance and the proxy\n  performs the OAuth flow against an external OIDC IdP on their behalf.\n  Useful when you don't have a server to host the proxy on or when the\n  upstream MCP only validates tokens and you want each developer to\n  authenticate locally.\n\n- [What Is This For?](#what-is-this-for)\n- [Prerequisites](#prerequisites)\n- [Web Connector (Recommended)](#web-connector-recommended)\n  - [How it works](#how-it-works)\n  - [Keycloak](#keycloak)\n  - [Generic OIDC](#generic-oidc)\n  - [AWS Cognito](#aws-cognito)\n  - [Google](#google)\n  - [Azure (Entra ID)](#azure-entra-id)\n  - [Connecting downstream MCP clients](#connecting-downstream-mcp-clients)\n  - [Identity advertised to downstream clients](#identity-adver…","publisher":null,"homepage":null,"repository":null,"version":"0.5.0","license":null,"protocols":["mcp"],"tags":["mcp"],"pricing":null,"endpoints":[{"url":"pypi:authsome-mcp-proxy","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","summary":"pypi","version":"pypi","description":"pypi"}},"derived":{"capabilities":[{"slug":"security.identity","name":"Identity & Access","confidence":1,"provenance":"derived"},{"slug":"infra.cloud","name":"Cloud Platforms","confidence":0.733,"provenance":"derived"}],"categories":["infra","security"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"authsome-mcp-proxy","registry":"pypi","observedAt":"2026-09-09T09:25:18.928Z","publishedAt":"2026-08-24T22:05:53.133839Z","latestVersion":"0.5.0"}},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"authsome-mcp-proxy","url":"https://pypi.org/project/authsome-mcp-proxy/","firstSeenAt":"2026-09-09T09:24:26.013Z","fetchedAt":"2026-09-09T09:24:26.013Z","normalizedAt":"2026-09-09T09:24:26.013Z"}]},"firstSeenAt":"2026-09-09T09:24:26.013Z","updatedAt":"2026-09-09T09:25:18.928Z"}