Skip to content

Repository files navigation

Authplane Rust SDK

License

Rust crates for OAuth 2.1 client flows, token verification, and MCP consent propagation with Authplane.

This repository is a Cargo workspace with a framework-agnostic core crate plus adapters for both the official Rust MCP SDK and FastMCP.

Packages

Crate Install command Purpose
authplane-sdk cargo add authplane-sdk Core OAuth 2.1 client helpers, token verification, DPoP helpers, and PRM generation.
authplane-mcp cargo add authplane-mcp Adapter helpers for rmcp, including URL-elicitation mapping for consent flows.
authplane-fastmcp cargo add authplane-fastmcp Adapter helpers for fastmcp-rust (stdio + HTTP), including URL-elicitation mapping.
authplane-conformance-tests (internal) Shared OAuth SDK conformance test suite

Capabilities

Standards and RFCs

  • OAuth 2.1 draft: authorization-server discovery, token endpoint helpers, and secure-by-default fetch settings.
  • RFC 8414: authorization server metadata discovery via AuthplaneClient with a MetadataCache that fires an on_change hook on rotation.
  • RFC 8693: token exchange request helpers and typed token-exchange error parsing.
  • RFC 7662: token introspection helpers and optional revocation checks during verification.
  • RFC 7009: token revocation helpers.
  • RFC 9068: JWT Profile for OAuth 2.0 Access Tokens (typ = at+jwt enforcement, required claims sub / client_id / exp / iat / jti).
  • RFC 9728: Protected Resource Metadata generation, and the resource_metadata parameter on every WWW-Authenticate challenge.
  • RFC 9449: outbound DPoP proof generation with per-origin nonce store and inbound DPoP verification with optional replay protection.
  • RFC 8707: repeated resource indicators in token and token-exchange requests.
  • RFC 7234: HTTP caching semantics on metadata and JWKS discovery responses (max-age, Expires, stale-cache fallback).
  • RFC 6750 / RFC 7519 / RFC 7517: bearer access-token verification over JWT/JWKS with typed claims access.

Security

  • HTTPS-only by default for outbound metadata, JWKS, token, introspection, and revocation requests.
  • Development-mode fetch settings that explicitly allow http://localhost and private networks when needed.
  • Outbound fetch hardening for literal localhost and private-network targets, plus redirect disabling when SSRF protection is enabled.
  • JWT validation with issuer, audience, signature, exp, nbf, future-iat, typ = at+jwt, and allowed-algorithm checks.
  • Algorithm-confusion defenses: only RS256 and ES256 (asymmetric) are accepted; none, HS256, HS384, and HS512 are always rejected at construction.
  • DPoP verification with htm, htu, ath, nonce, age, and cnf.jkt binding checks; optional DpopReplayStore for jti replay protection.
  • JWKS resilience: background refresh at 80% of TTL, force-refresh on kid miss with a minimum refresh interval, stale-cache fallback on transient fetch errors.
  • Token caching with TTL buffer for client_credentials results.
  • Stateful circuit breaker (closed/open/half-open) wrapping every outbound AS call.

Framework Integrations

Requirements

  • Rust 1.91 or newer (edition 2024)
  • A Tokio runtime for async client and verifier flows

Compatibility

Tested against authserver 0.2.0. Introspection-based revocation requires authserver 0.1.2 or newer, and a confidential client that is the issuing client or a runtime-client of the resource — older releases and other callers answer active: false for every token.

Documentation

Status

Crate crates.io docs.rs
Core SDK crates.io docs.rs
MCP adapter crates.io docs.rs
FastMCP adapter crates.io docs.rs

License

Apache 2.0. See LICENSE.

About

AuthPlane SDK for Rust — OAuth 2.1 token verification, DPoP, and MCP adapters.

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages