The mcpresource module is a zero-dependency Go module for MCP resource servers. It validates bearer JWTs, enforces audience claims, walks RFC 8693 actor chains via AS introspection, and emits the correct WWW-Authenticate response on failure.
Install
mcpresource has no third-party dependencies. Importing it does not pull in theauth core or any storage adapter.
Wire the middleware
What the middleware validates
On every request the middleware:
- Extracts the bearer token from the
Authorization: Bearer ... header.
- Verifies the JWT signature against a cached JWKS (refreshes on
kid miss and at the configured cache TTL).
- Enforces the
aud claim against the resource URI passed to mcpresource.New.
- Checks
exp, nbf, and iat with a 60-second clock skew tolerance (configurable).
- Walks the RFC 8693
act chain via AS introspection and returns active: false if any delegation grant in the chain is revoked.
- On any failure: emits HTTP 401 with
WWW-Authenticate: Bearer error="invalid_token", resource_metadata="..." per RFC 6750 and RFC 9728.
The Principal type
Options
Concurrent safety
The JWKS and introspection caches use sync.RWMutex internally so concurrent reads do not serialize. Cache writes (on miss or TTL expiry) take a write lock for the minimum duration.
Runnable example
See examples/mcp-server/ for a complete standalone demo. Last modified on October 7, 2026