Back to the red bull cans

Solo build

MCP server with JWT auth

A secure way to give AI assistants tools over the internet

BuiltApr 2025GitHub (4 stars)

Video in the works

MCP server with JWT auth

Getting a token, connecting MCP Inspector, and calling a protected tool.

About the project

MCP is a standard way to give AI assistants tools. In early 2025 almost every MCP tool server ran on your own computer. This one runs online, and only lets in assistants that carry a login token (a JWT).

MCP, the Model Context Protocol, lets an AI use tools that live on a server. In early 2025 almost every MCP server ran on your own computer. This one runs over the internet, and no client gets in without a token.

It's a small public demo that other developers found useful: 4 stars, 2 forks, and a pull request from someone I'd never met.

How it works

  1. Get a token

    Call the token route and receive a JWT that lasts one hour.

  2. Connect

    Open the event stream with the token. A fresh MCP server is created for this session.

  3. Call tools

    Send messages with the session ID. They're checked for the same token and routed to the right session.

  4. Leave

    When the connection closes, the session is cleaned up.

Under the hood

Server
Express 5 with the MCP SDK's SSE transport.
Auth
JWT middleware on both the stream and the message route.
Tools
4 demo tools with inputs checked by Zod.

What I did

  • Put the MCP SDK behind an Express server
  • JWT middleware: 401 with no token, 403 with a bad one, and the user's details passed on
  • Both the event stream and the message endpoint behind the same check
  • A route that issues a one-hour token
  • A fresh MCP server for each connection, with messages routed to the right session and closed sessions cleaned up
  • 4 demo tools with checked inputs, and a step-by-step test guide with MCP Inspector

What was new

  • Remote MCP over HTTP, when most people ran it locally
  • People outside used it: stars, forks, and a pull request from a stranger

Problems I hit, and how I fixed them

  1. Express didn't know about the decoded user on each request, so TypeScript complained.

    Fix A type declaration for it.

  2. Each message must reach the right live session.

    Fix Look sessions up by ID, return 404 if there's none, and remove them on close.

Screenshots

Screenshots in the works

Real screens from MCP server with JWT auth go here.

To be clear

It's a demo, not production auth: anyone can get a token from the token route, and it doesn't check roles yet, even though a commit message says so. A fresh clone also needs the JWT library added to package.json.