MCP OAuth Token Audience Security Audit
Compare MCP resource and authorization metadata, detect unsafe token audience assumptions, and log a focused security review.
The full canvas, before you import it
Click any node to see its config.
Click a node to select it — same as the Heym editor; the panel shows its settings.
10 nodes · Free & source-available
MCP OAuth Token Audience Security Audit
Review the public OAuth metadata around a protected Model Context Protocol server. The workflow fetches resource and authorization server documents in parallel, then checks audience declarations, issuer alignment, supported challenges, and signs of token passthrough risk.
What this workflow does
- McpSecurityRequest captures the protected resource and authorization metadata URLs
- FetchResourceMetadata loads the MCP protected resource declaration
- FetchAuthorizationMetadata loads the authorization server declaration
- MergeMcpSecurityMetadata joins both responses
- AuditMcpOAuthMetadata produces a structured security assessment
- McpRiskGate separates risky configurations from clean reviews
- Risky findings are logged and sent to Slack
- Clean findings return a compact audit receipt
Use cases
- MCP OAuth security reviews
- Token audience validation checks
- Authorization server metadata audits
- MCP gateway launch checklists
Setup
Enter the exact well-known metadata URLs published by your MCP deployment. Connect an LLM credential, DataTable, and Slack. Verify findings with your identity and security teams before changing production authorization policies.
How to import this template
- 1Click Import → Copy JSON on this page.
- 2Open your Heym and navigate to a workflow canvas.
- 3PressCmd+V/Ctrl+V— nodes appear instantly.
- 4Add your API keys in the node config panels and click Run.
Discover more automations
- Dev & IT OpsHTML Status PageCheck an upstream service and answer a browser GET with a rendered status page instead of JSON.
- Dev & IT OpsWorkflow Change Audit LogCapture every workflow create, update, and delete on your Heym instance and post a batched summary to Slack.
- Dev & IT OpsCodex PR Fix AgentSend a coding task to Codex, open a draft PR when it succeeds, and notify Slack when Codex needs follow-up input.
- Dev & IT OpsOpenCode Go PR Fix AgentSend a coding task to OpenCode Go, open a review-ready pull request, and return the implementation result.
- Dev & IT OpsAgent-Guided Codex PR DispatcherLet an Agent inspect a GitHub request, prepare a confirmed Codex task, open a ready PR, and notify Slack when Codex needs input.
- Dev & IT OpsCursor Post NotifierMonitor the Cursor blog on a schedule and Slack-notify your team when a new post goes live.
- Dev & IT OpsClaude Blog MonitorMonitor the Anthropic blog on a schedule and Slack-notify your team on new Claude posts.
- Dev & IT OpsGitHub Release RadarCompare the latest GitHub release tag against Redis and notify Slack when a project ships a new version.
- Dev & IT Opsweb.dev Article MonitorCron + crawler + Redis dedupe + Slack: get notified when Google's web.dev blog publishes a new article.
- Dev & IT OpsCloudback MCP Backup Coverage ReviewReview Cloudback backup coverage with a Docker-based MCP server, gate configuration changes with HITL, and notify ops in Slack.
- Dev & IT OpsResilient HTTP + Error HandlerAttach an Error Handler node to an HTTP call and Slack-notify your team the moment a request fails.
- Dev & IT OpsPlaywright Visual AI MonitorTake a full-page screenshot on a schedule, analyse it with an LLM for anomalies, and Slack-alert when something looks off.