Expand description
Access enforcement for proxied MCP and agent requests.
AccessValidator resolves whether a service requires OAuth, validates the
caller’s bearer token and scopes, and either returns the authenticated user
or converts the failure into an RFC 9728 challenge. For MCP it permits a
session-only fallback when a prior authenticated initialize established the
identity in the proxy cache.
Copyright (c) systemprompt.io — Business Source License 1.1. See https://systemprompt.io for licensing details.