This is a minimal MCP server that acts as an OAuth Resource Server. It does not issue tokens of its own. It accepts JWT access tokens issued by an external authorization server and validates them locally on every request.
| Endpoint | Role |
|---|---|
https://mcp.tinywiki.xyz/mcp |
The MCP server (Streamable HTTP). Requires a valid access token. |
https://mcp.tinywiki.xyz/motd |
When presented with a valid access token, returns the message of the day |
https://mcp.tinywiki.xyz/userinfo |
Echoes back the validated claims from your access token |
https://mcp.tinywiki.xyz/.well-known/oauth-protected-resource/mcp |
Protected resource metadata (RFC 9728), pointing at the authorization server |
Tokens are issued by the authorization server below, not by this server:
https://aparecki-dev.okta.com/oauth2/aus26n9v6838N9rpQ1d8https://mcp.tinywiki.xyz/An MCP client discovers all of this on its own: it calls /mcp without a token, gets a 401 with a WWW-Authenticate challenge naming the metadata URL, follows that to the authorization server, and runs a normal authorization code flow.
On every request this server checks that the token:
none, never symmetric)iss, matched as an exact stringaudexp/nbf windowkidThe issuer's key set is cached, so validation normally costs no network requests. See lib/token.php.