Skip to content

v0.9.5: Minimal OAuth Implementation for Claude.ai

Choose a tag to compare

@ma3u ma3u released this 26 Jul 16:11
· 44 commits to main since this release

🔐 Minimal OAuth for Claude.ai Compatibility

This release implements a minimal OAuth flow that auto-approves Claude.ai connections without requiring actual authentication.

Why This Change?

Claude.ai continues to attempt OAuth authentication even when we tell it OAuth is not enabled. This minimal implementation satisfies Claude.ai's OAuth requirements while not requiring any actual authentication.

What's New

  • Minimal OAuth implementation that auto-approves Claude.ai
  • OAuth flow returns proper 302 redirects with authorization codes
  • Token endpoint returns dummy bearer tokens
  • All without requiring actual authentication

Configuration

Set these environment variables in Railway:

  • CLAUDE_AI_SKIP_OAUTH=false
  • CLAUDE_AI_MINIMAL_OAUTH=true

How It Works

  1. Claude.ai requests /authorize → Server auto-approves and redirects with auth code
  2. Claude.ai exchanges code for token → Server returns dummy bearer token
  3. Claude.ai can now connect to the MCP server

Testing

Check the OAuth mode:

curl https://strunz.up.railway.app/debug/env
# Should show: oauth_mode: minimal

Test authorize endpoint:

curl -I 'https://strunz.up.railway.app/authorize?client_id=claude_test&redirect_uri=https://claude.ai/callback'
# Should return: 302 redirect

🤖 Generated with Claude Code

Co-Authored-By: Claude noreply@anthropic.com