mcp-authscan
PulseGate's liveness check found it on 4 Oct 2026; it is registered on GitHub and PyPI and has been in the index since 4 Oct 2026. How this is checked
mcp-authscan is an open-source command-line static security scanner for self-implemented OAuth and authentication flows in MCP servers, gateways, and OAuth clients. It detects failure classes related to OAuth and PKCE and can emit SARIF results for GitHub code scanning.
Inferred · not functionally tested
Overview
6 featuresPurpose: Finding OAuth and authentication vulnerabilities in MCP servers, gateways, and clients before deployment.
Inferred · not functionally tested
Audience: security engineers and developers building MCP servers or OAuth clients
Inferred · not functionally tested
Functions: monitoring
Inferred · not functionally tested
Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: pypi.org · github.com. These links do not verify the individual claims.
mcp-authscan is an Application security & vulnerability scanning project. Inferred · not functionally tested: It focuses on finding OAuth and authentication vulnerabilities in MCP servers, gateways, and clients before deployment. Inferred · not functionally tested: mcp-authscan is an open-source project aimed at security engineers and developers building MCP servers or OAuth clients. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It ships for the command line, and it can be self-hosted.
LHMisme420 builds and maintains mcp-authscan, and it first shipped in 2026. The project is developed in the open on GitHub with 20 commits in the last 90 days. Inferred · not functionally tested: Among its 6 catalogued features are OAuth scanning, PKCE checks, and SAST rules.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- OAuth scanning
- PKCE checks
- SAST rules
- MCP analysis
- SARIF output
- GitHub code scanning
Topics: Inferred · not functionally tested
Built with & integrations
Trust & compliance
Indexing history
5What PulseGate has recorded for this listing
- Indexed4 Oct · 21:33 UTCmcp-authscan seen via PyPI Bulk EnumeratorSource: PyPI Bulk Enumerator · Open
Frequently asked questions about mcp-authscan
- What does mcp-authscan do?
- Inferred · not functionally tested: Mcp-authscan focuses on finding OAuth and authentication vulnerabilities in MCP servers, gateways, and clients before deployment. It is catalogued under Application security & vulnerability scanning on PulseGate.
- Who is mcp-authscan for?
- Inferred · not functionally tested: mcp-authscan is an open-source project built for security engineers and developers building MCP servers or OAuth clients.
- Does mcp-authscan have a free plan?
- Basis unknown · not verified: Yes — mcp-authscan is open source under the MIT license and free to use.
- What platforms does mcp-authscan run on?
- Basis unknown · not verified: mcp-authscan runs on the command line. It can also be self-hosted.
- Is mcp-authscan still maintained?
- PulseGate's liveness check found it on 4 Oct 2026. Its GitHub repository shows 20 commits in the last 90 days.
- What projects are similar to mcp-authscan?
- Similar projects tracked by PulseGate include mcp-security-scan, mcpsecscan, and mcp-safety.mcp-security-scanmcpsecscanmcp-safety
- Who develops mcp-authscan?
- mcp-authscan is developed by LHMisme420.
- How long has mcp-authscan been around?
- mcp-authscan first shipped in 2026.
Similar projects
Closest matches by what these projects do