Rust crates for OAuth 2.1 client flows, token verification, and MCP consent propagation with Authplane.
This repository is a Cargo workspace with a framework-agnostic core crate plus adapters for both the official Rust MCP SDK and FastMCP.
| Crate | Install command | Purpose |
|---|---|---|
authplane-sdk |
cargo add authplane-sdk |
Core OAuth 2.1 client helpers, token verification, DPoP helpers, and PRM generation. |
authplane-mcp |
cargo add authplane-mcp |
Adapter helpers for rmcp, including URL-elicitation mapping for consent flows. |
authplane-fastmcp |
cargo add authplane-fastmcp |
Adapter helpers for fastmcp-rust (stdio + HTTP), including URL-elicitation mapping. |
authplane-conformance-tests |
(internal) | Shared OAuth SDK conformance test suite |
- OAuth 2.1 draft: authorization-server discovery, token endpoint helpers, and secure-by-default fetch settings.
- RFC 8414: authorization server metadata discovery via
AuthplaneClientwith aMetadataCachethat fires anon_changehook on rotation. - RFC 8693: token exchange request helpers and typed token-exchange error parsing.
- RFC 7662: token introspection helpers and optional revocation checks during verification.
- RFC 7009: token revocation helpers.
- RFC 9068: JWT Profile for OAuth 2.0 Access Tokens (
typ = at+jwtenforcement, required claimssub/client_id/exp/iat/jti). - RFC 9728: Protected Resource Metadata generation, and the
resource_metadataparameter on everyWWW-Authenticatechallenge. - RFC 9449: outbound DPoP proof generation with per-origin nonce store and inbound DPoP verification with optional replay protection.
- RFC 8707: repeated
resourceindicators in token and token-exchange requests. - RFC 7234: HTTP caching semantics on metadata and JWKS discovery responses (
max-age,Expires, stale-cache fallback). - RFC 6750 / RFC 7519 / RFC 7517: bearer access-token verification over JWT/JWKS with typed claims access.
- HTTPS-only by default for outbound metadata, JWKS, token, introspection, and revocation requests.
- Development-mode fetch settings that explicitly allow
http://localhostand private networks when needed. - Outbound fetch hardening for literal localhost and private-network targets, plus redirect disabling when SSRF protection is enabled.
- JWT validation with issuer, audience, signature,
exp,nbf, future-iat,typ = at+jwt, and allowed-algorithm checks. - Algorithm-confusion defenses: only
RS256andES256(asymmetric) are accepted;none,HS256,HS384, andHS512are always rejected at construction. - DPoP verification with
htm,htu,ath, nonce, age, andcnf.jktbinding checks; optionalDpopReplayStoreforjtireplay protection. - JWKS resilience: background refresh at 80% of TTL, force-refresh on
kidmiss with a minimum refresh interval, stale-cache fallback on transient fetch errors. - Token caching with TTL buffer for
client_credentialsresults. - Stateful circuit breaker (closed/open/half-open) wrapping every outbound AS call.
authplane-sdk: framework-agnostic primitives.authplane-mcp:rmcpadapter.authplane-fastmcp:fastmcp-rustadapter (stdio + HTTP).
- Rust 1.91 or newer (edition 2024)
- A Tokio runtime for async client and verifier flows
Tested against authserver 0.2.0. Introspection-based revocation requires authserver 0.1.2 or newer, and a confidential client that is the issuing client or a runtime-client of the resource — older releases and other callers answer active: false for every token.
core/README.mdandcore/docs/user-guide.mdmcp/README.mdandmcp/docs/user-guide.mdfastmcp/README.mdandfastmcp/docs/user-guide.mdCHANGELOG.mdSECURITY.mdCONTRIBUTING.mdRELEASE_POLICY.md
| Crate | crates.io | docs.rs |
|---|---|---|
| Core SDK | ||
| MCP adapter | ||
| FastMCP adapter |
Apache 2.0. See LICENSE.