Internal MCP Server

This is a minimal MCP server that acts as an OAuth Resource Server. It does not issue tokens of its own. It accepts JWT access tokens issued by an external authorization server and validates them locally on every request.

Endpoint Role
https://mcp.tinywiki.xyz/mcp The MCP server (Streamable HTTP). Requires a valid access token.
https://mcp.tinywiki.xyz/motd When presented with a valid access token, returns the message of the day
https://mcp.tinywiki.xyz/userinfo Echoes back the validated claims from your access token
https://mcp.tinywiki.xyz/.well-known/oauth-protected-resource/mcp Protected resource metadata (RFC 9728), pointing at the authorization server

Getting an access token

Tokens are issued by the authorization server below, not by this server:

An MCP client discovers all of this on its own: it calls /mcp without a token, gets a 401 with a WWW-Authenticate challenge naming the metadata URL, follows that to the authorization server, and runs a normal authorization code flow.

How a token is validated

On every request this server checks that the token:

  1. is a JWT signed with an accepted algorithm (never none, never symmetric)
  2. names a configured authorization server in iss, matched as an exact string
  3. names this API in aud
  4. is currently within its exp/nbf window
  5. carries a valid signature from the issuer's published key, looked up by kid
  6. carries any required scopes

The issuer's key set is cached, so validation normally costs no network requests. See lib/token.php.