Validate Casdoor tokens in your MCP server
This guide contains complete MCP servers in Python, Node.js, and Go that use Casdoor as their authorization server. Each one publishes Protected Resource Metadata, validates tokens, and checks scopes.
Learning outcomes
- Run an MCP server that validates Casdoor tokens.
- Connect it to Claude Desktop.
- Prepare the server for production.
What you need
- Casdoor configured for your MCP server. See Set up Casdoor for your MCP server.
- An MCP client for testing, such as Claude Desktop
注意
To keep the examples short, some of them comment out parts of the token validation. Before you deploy a server, turn the validation on and validate every request.
Python
The example uses the official mcp SDK and PyJWT.
-
Install the packages:
pip install mcp PyJWT cryptography requests -
Save the following code as
mcp_server.py:"""
MCP Server with Casdoor OAuth Authentication
Demonstrates Protected Resource Metadata, JWT validation, and scope enforcement
"""
import asyncio
import json
from typing import Any
import jwt
import requests
from jwt import PyJWKClient
from mcp.server import Server
from mcp.server.stdio import stdio_server
from mcp.types import Tool, TextContent
# Configuration - Replace with your Casdoor instance
CASDOOR_URL = "https://your-casdoor.com"
MCP_SERVER_URL = "https://your-mcp-server.com"
JWKS_URL = f"{CASDOOR_URL}/.well-known/jwks"
# Initialize JWKS client for token validation
jwks_client = PyJWKClient(JWKS_URL)
# Create MCP server instance
app = Server("example-mcp-server")
def validate_token(token: str) -> dict:
"""
Validate JWT token from Casdoor using JWKS.
Returns decoded token with claims if valid.
Raises jwt.InvalidTokenError if invalid.
"""
try:
# Get signing key from JWKS
signing_key = jwks_client.get_signing_key_from_jwt(token)
# Verify and decode token
decoded = jwt.decode(
token,
signing_key.key,
algorithms=["RS256"],
audience=MCP_SERVER_URL, # Verify audience matches our server
options={
"verify_signature": True,
"verify_exp": True,
"verify_aud": True,
}
)
return decoded
except jwt.InvalidTokenError as e:
raise ValueError(f"Invalid token: {e}")
def check_scope(token_data: dict, required_scope: str) -> None:
"""
Check if token contains required scope.
Raises PermissionError if scope is missing.
"""
scopes = token_data.get("scope", "").split()
if required_scope not in scopes:
raise PermissionError(f"Missing required scope: {required_scope}")
@app.list_tools()
async def list_tools() -> list[Tool]:
"""List available tools"""
return [
Tool(
name="read_file",
description="Read contents of a file",
inputSchema={
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the file to read"
}
},
"required": ["path"]
}
),
Tool(
name="write_file",
description="Write content to a file",
inputSchema={
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Path to the file to write"
},
"content": {
"type": "string",
"description": "Content to write to the file"
}
},
"required": ["path", "content"]
}
),
Tool(
name="list_files",
description="List files in a directory",
inputSchema={
"type": "object",
"properties": {
"path": {
"type": "string",
"description": "Directory path to list"
}
},
"required": ["path"]
}
)
]
@app.call_tool()
async def call_tool(name: str, arguments: Any) -> list[TextContent]:
"""
Handle tool calls with OAuth token validation and scope enforcement.
In production, extract token from request context.
For this example, we'll show the validation logic.
"""
# In a real MCP server, extract token from the request headers
# token = request.headers.get("Authorization", "").replace("Bearer ", "")
# For demonstration, we'll skip actual token extraction
# Example token validation (uncomment in production):
# try:
# token_data = validate_token(token)
# except ValueError as e:
# return [TextContent(type="text", text=f"Authentication failed: {e}")]
# Handle each tool with appropriate scope checks
if name == "read_file":
# Requires files:read scope
# check_scope(token_data, "files:read")
path = arguments.get("path")
try:
with open(path, 'r') as f:
content = f.read()
return [TextContent(
type="text",
text=f"File contents:\n{content}"
)]
except Exception as e:
return [TextContent(
type="text",
text=f"Error reading file: {e}"
)]
elif name == "write_file":
# Requires files:write scope
# check_scope(token_data, "files:write")
path = arguments.get("path")
content = arguments.get("content")
try:
with open(path, 'w') as f:
f.write(content)
return [TextContent(
type="text",
text=f"Successfully wrote to {path}"
)]
except Exception as e:
return [TextContent(
type="text",
text=f"Error writing file: {e}"
)]
elif name == "list_files":
# Requires files:list scope
# check_scope(token_data, "files:list")
import os
path = arguments.get("path")
try:
files = os.listdir(path)
return [TextContent(
type="text",
text=f"Files in {path}:\n" + "\n".join(files)
)]
except Exception as e:
return [TextContent(
type="text",
text=f"Error listing files: {e}"
)]
return [TextContent(type="text", text=f"Unknown tool: {name}")]
async def serve_protected_resource_metadata():
"""
Serve Protected Resource Metadata endpoint.
In production, integrate this with your HTTP framework.
"""
metadata = {
"resource": MCP_SERVER_URL,
"authorization_servers": [CASDOOR_URL],
"scopes_supported": [
"files:read",
"files:write",
"files:list"
],
"bearer_methods_supported": ["header"]
}
return metadata
async def main():
"""Run the MCP server"""
async with stdio_server() as (read_stream, write_stream):
await app.run(
read_stream,
write_stream,
app.create_initialization_options()
)
if __name__ == "__main__":
asyncio.run(main()) -
Add the server to the Claude Desktop configuration, on macOS
~/Library/Application Support/Claude/claude_desktop_config.json:{
"mcpServers": {
"example-files": {
"command": "python",
"args": ["/path/to/mcp_server.py"]
}
}
} -
Restart Claude Desktop and check that the tools appear.