FeaturedDev & IT Ops#MCP Security#Model Context Protocol#OAuth 2.1#Token Audience#Authorization#AI Security

MCP OAuth Token Audience Security Audit

Compare MCP resource and authorization metadata, detect unsafe token audience assumptions, and log a focused security review.

Workflow at a glance

The full canvas, before you import it

Click any node to see its config.

#MCP Security#Model Context Protocol#OAuth 2.1#Token Audience#Authorization#AI Security

Click a node to select it — same as the Heym editor; the panel shows its settings.

10 nodes · Free & source-available

MCP OAuth Token Audience Security Audit

Review the public OAuth metadata around a protected Model Context Protocol server. The workflow fetches resource and authorization server documents in parallel, then checks audience declarations, issuer alignment, supported challenges, and signs of token passthrough risk.

What this workflow does

  1. McpSecurityRequest captures the protected resource and authorization metadata URLs
  2. FetchResourceMetadata loads the MCP protected resource declaration
  3. FetchAuthorizationMetadata loads the authorization server declaration
  4. MergeMcpSecurityMetadata joins both responses
  5. AuditMcpOAuthMetadata produces a structured security assessment
  6. McpRiskGate separates risky configurations from clean reviews
  7. Risky findings are logged and sent to Slack
  8. Clean findings return a compact audit receipt

Use cases

  • MCP OAuth security reviews
  • Token audience validation checks
  • Authorization server metadata audits
  • MCP gateway launch checklists

Setup

Enter the exact well-known metadata URLs published by your MCP deployment. Connect an LLM credential, DataTable, and Slack. Verify findings with your identity and security teams before changing production authorization policies.

How to import this template

  1. 1Click Import → Copy JSON on this page.
  2. 2Open your Heym and navigate to a workflow canvas.
  3. 3PressCmd+V/Ctrl+V— nodes appear instantly.
  4. 4Add your API keys in the node config panels and click Run.
More workflow templates
View all templates
Heym
incident analysis · production AI
Observed across 100s of AI rollouts

AI workflows don't fail because of prompts.
They fail because of orchestration.

symptom · glue code01
5 tools
Scripts, vector DB, approval bot, tracing, browser runner — none of them talk.
symptom · visibility02
~0%
Observable behavior across the stack. Debugging is guesswork.
with heym · one runtime
1 canvas
Agents, RAG, HITL, MCP, traces & evals. Self-hosted. Observable.
AI-Native RuntimeProduction-Grade
github.com/heymrun/heym