{"name":"io.github.lonniev/tollbooth-oauth2-collector","slug":"lonniev-tollbooth-oauth2-collector","title":null,"description":"Unauthenticated OAuth2 callback collector for Tollbooth MCP services","url":"https://mcp.market/server/lonniev-tollbooth-oauth2-collector","rating":null,"grade":"A","score":91,"certified":false,"status":"active","category":"other","tags":[],"presence":{"score":20,"stars":0,"forks":0,"downloads_week":null,"last_push_at":"2026-09-02T20:09:27.000Z","license":"Apache-2.0"},"uptime":{"percent":100,"checks":8,"ok":8,"last_checked_at":"2026-09-21T10:01:15.777Z","last_ok_at":"2026-09-21T10:01:15.777Z","latency_ms":331},"claimed":false,"transport":"remote","callable_via_gateway":true,"default_price_micros":0,"repository":"https://github.com/lonniev/tollbooth-oauth2-collector","website":null,"version":"0.2.11","remotes":[{"type":"streamable-http","url":"https://tollbooth-oauth2-collector.fastmcp.app/mcp"}],"packages":[],"tools":[{"name":"collector_status","description":"Health check — shows the number of pending authorization codes and TTL.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"retrieve_code","description":"Retrieve a stored authorization code (one-time read, auto-deleted).\n\nCalled by the originating MCP server to pick up the code after the user\nhas authorized in the browser. Returns the encrypted code which the\ncaller decrypts using the same state token.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"state":{"type":"string","description":"The state token (patron npub) used during authorization."}},"required":["state"],"additionalProperties":false}},{"name":"service_status","description":"Report the running build so a redeploy can be verified. Free.\n\nDelegates to the SDK's canonical ``build_service_status`` — the single\nsource of the service_status payload shape — so this collector reports the\nsame envelope as every other DPYC service. The load-bearing field is\n``build_info.fastmcp_cloud_git_commit_sha``: the commit Horizon actually\ndeployed. The post-merge deploy-verify probe reads it to confirm the live\nservice redeployed the merged sha; with no ``service_status`` tool to probe,\nthat sha reads as ``<none>`` and an otherwise-healthy deploy is flagged as\n\"did not land\".\n\nThe vault/courier/operator fields are ``False``/empty by construction —\nthis is an unauthenticated community utility with no operator runtime.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{},"additionalProperties":false}},{"name":"store_code","description":"Store a sealed OAuth2 authorization code.\n\nCalled by the serverless callback function after the browser redirect. The\n``state`` carries BOTH the patron npub (the lookup/retrieve key) and the\noperator npub (the PUBLIC key the code is sealed to) — see the SDK's\n``pack_oauth_state``. The code is sealed with NIP-44 to the operator so only\nthat operator's nsec can open it; the Neon row is keyed by the patron npub,\nso retrieval (``retrieve_code(state=patron_npub)``) is unchanged.","write_action":false,"price_micros":0,"input_schema":{"type":"object","properties":{"code":{"type":"string","description":"The authorization code from the OAuth provider."},"state":{"type":"string","description":"The packed state (``patron_npub.operator_npub``)."}},"required":["code","state"],"additionalProperties":false}}],"scan":{"score":91,"grade":"A","scanned_at":"2026-09-21T13:06:11.035Z","report":{"scannerVersion":"0.1.9","scannedAt":"2026-09-21T13:06:11.024Z","components":{"code":{"score":-1,"max":25,"notes":["remote-only server, no package to scan"]},"reliability":{"score":20,"max":20,"notes":["remote reachable in 1266ms"]},"poisoning":{"score":15,"max":15,"notes":["4 tool descriptions checked"]},"auth":{"score":10,"max":15,"notes":["open endpoint, read-only tools"]},"maintenance":{"score":15,"max":15,"notes":["last push 19 days ago"]},"identity":{"score":8,"max":10,"notes":["registry namespace matches repository owner","GitHub account older than a year"]}},"findings":[],"inputs":{"probes":[{"url":"https://tollbooth-oauth2-collector.fastmcp.app/mcp","reachable":true,"authRequired":false,"latencyMs":1266,"serverInfo":{"name":"Tollbooth OAuth2 Collector","version":"3.4.7"}}],"packages":[],"repo":{"found":true,"owner":"lonniev","repo":"tollbooth-oauth2-collector","archived":false,"pushedAt":"2026-09-02T20:09:27Z","stars":0,"forks":0,"openIssues":0,"ownerType":"User","ownerAvatarUrl":"https://avatars.githubusercontent.com/u/2193384?v=4","ownerCreatedAt":"2012-08-22T02:07:21Z","license":"Apache-2.0"},"icon":{"url":"https://avatars.githubusercontent.com/u/2193384?v=4&s=128","source":"github"},"presence":{"stars":0,"forks":0,"downloadsWeek":null,"license":"Apache-2.0","lastPushAt":"2026-09-02T20:09:27.000Z","score":20}}}},"grade_history":[],"reviews":[]}