PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteTo add OAuth to an MCP server, treat the server as an OAuth-protected HTTP resource, not as the component that issues tokens. An authorization server (usually an identity provider) authenticates the user and issues an access token; your MCP server publishes Protected Resource Metadata, challenges unauthenticated requests, validates that token for its own audience, and enforces scopes before running tools or returning resources.
This guide follows the versioned 2026-07-28 MCP specification. Its authorization flow is for remote HTTP transports. A local stdio server normally receives credentials through its environment or an embedded configuration instead of using this browser-based OAuth flow.
When OAuth is the right MCP design
Use OAuth when an MCP server exposes user-specific data, sensitive actions, APIs that require user consent, audit trails, or enterprise access controls. A public, read-only service may need no login, or may protect only selected tools. Decide the boundary before writing middleware.
Remote HTTP versus local stdio
| Deployment | Typical credential model | What you must operate |
|---|---|---|
| Remote HTTP MCP server | OAuth access token in the HTTP Authorization header | Protected Resource Metadata, bearer challenges, token validation, scopes, redirects and provider integration |
| Local stdio MCP server | Environment variables, a local credential store, or an embedded login flow | Process and local secret handling; the remote MCP OAuth discovery flow is not automatically applicable |
Do not assume that a client supporting stdio also supports every remote registration or PKCE variation. Test the exact client, identity provider and deployment path you intend to support.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
Understand the two-server architecture
Your MCP service is the protected resource/resource server. It accepts MCP HTTP requests and decides whether a token may invoke a particular operation. A separate authorization server or identity provider signs or returns tokens after authenticating the user. The MCP server does not have to mint its own tokens.
Responsibilities
- Authorization server: user login and consent, authorization-code exchange, PKCE handling, client registration policy, signing keys and token issuance.
- MCP resource server: canonical resource identifier, metadata publication, HTTP challenges, signature or introspection checks, issuer and audience checks, expiry checks, and scope enforcement.
- MCP client: discovery, redirect handling, PKCE, authorization and token requests, then sending the resulting bearer token to the MCP endpoint.
You can use a managed provider or operate an authorization server yourself. In either case, verify that it supports the discovery, resource indication, PKCE and registration behavior required by your target clients.
Build sequence for a remote MCP server
- Choose the resource boundary. Record the HTTPS origin and path clients will call. Decide whether every MCP request requires a token or whether public tools remain open while sensitive tools require specific scopes.
- Select the authorization server. Configure a provider tenant, issuer, signing keys, allowed redirect URIs and scopes, or deploy those capabilities yourself. Keep the provider independent from the MCP request handler.
- Publish Protected Resource Metadata. Implement the OAuth Protected Resource Metadata format from RFC 9728. It must identify the protected resource, list the authorization server(s) that can issue tokens for it, and describe supported scopes where applicable.
- Implement authorization-code plus PKCE. The client discovers your metadata, discovers the provider, sends the canonical
resourceidentifier in authorization and token requests, authenticates the user, and presents the resulting access token to your MCP endpoint. - Validate every token for this resource. Check cryptographic signature or introspection status, issuer, expiration, audience/resource binding and required scopes before dispatching an MCP method.
- Return the protocol-appropriate response. Missing or invalid credentials receive an authentication challenge. A valid token lacking permission must be reported as insufficient authorization, not treated as an authentication failure.
- Test the complete path. Exercise metadata retrieval, redirects, PKCE, token expiry, wrong audience, missing scopes, provider key rotation, malformed headers and downstream API calls with your actual clients.
Publish Protected Resource Metadata correctly
Clients need a machine-readable answer to “which authorization server can issue a token for this MCP resource?” Serve an RFC 9728 document at the well-known location derived from the protected resource URL. The current MCP specification defines the construction; do not copy a legacy tutorial’s fixed path without checking how your resource path maps to the well-known URL.
A conceptual document looks like this (replace every example value with your deployment values):
{
"resource": "https://mcp.example.com/mcp",
"authorization_servers": [
"https://id.example.com"
],
"scopes_supported": [
"mcp:read",
"mcp:write"
]
}
Serve it as application/json without requiring a bearer token. The protected endpoint should point an unauthenticated client to that metadata through its bearer challenge. Keep the resource identifier stable: it is the value clients and authorization servers use to bind a token to your MCP service.
Implement the client authorization flow
Discovery and registration
The client first fetches resource metadata, then the authorization server’s metadata. The current specification prefers Client ID Metadata Documents (CIMD) for client identification. Dynamic Client Registration (DCR) remains for backward compatibility. Support the method your client/provider pair actually offers; do not present DCR as the only current option.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
PKCE and the resource parameter
The client should inspect authorization-server metadata to verify PKCE support. When technically capable, it should use the S256 code challenge method and refuse a silent downgrade when the server does not advertise the required capability. Authorization and token requests include the resource parameter naming your MCP resource so the resulting token is audience-bound.
Illustrative request sequence
- GET the protected-resource metadata URL.
- GET the provider metadata URL discovered in
authorization_servers. - Create a random PKCE verifier and its S256 challenge.
- Redirect the user to the provider’s authorization endpoint with client identity, redirect URI, code challenge, requested scopes and
resource=https://mcp.example.com/mcp. - Exchange the returned code at the provider’s token endpoint, sending the verifier and the same resource identifier.
- Call the MCP endpoint with
Authorization: Bearer ACCESS_TOKEN.
Redirect URI exactness, consent screens and registration fields are provider-specific. Keep those values in configuration, never in tool arguments or source code.
Free tools Windows power users keep installed
One-click scans. No signup required.
Enforce authentication at the HTTP boundary
Run authentication middleware before MCP message dispatch. A minimal decision tree is:
- No Authorization header: return
401with a bearer challenge that identifies the protected-resource metadata location. - Malformed, expired, unverifiable or wrong-issuer token: return
401; do not invoke the tool. - Valid token issued for another audience/resource: return
401; issuer familiarity alone is not sufficient. - Valid token with insufficient scope: return the specification-appropriate insufficient-permission response (commonly
403) and do not invoke the operation. - Valid token with the required permission: attach a normalized principal and scope set to the MCP request context, then dispatch.
A bearer challenge should lead clients to the correct metadata document. Keep error bodies free of token contents, signatures and provider internals. Handler-level checks are useful defense in depth, but they do not replace transport-level enforcement.
Token checks to perform
- Signature or introspection: verify against the provider’s current keys or an active introspection response.
- Issuer: accept only the configured issuer, including its exact tenant or realm.
- Expiration and time claims: reject expired tokens and allow only a small, documented clock-skew window.
- Audience/resource: require the MCP resource identifier, not merely a trusted issuer.
- Scopes or permissions: map each sensitive tool/resource to explicit permissions.
- Token type and transport: accept bearer credentials only over HTTPS in production; never log the raw token.
Design scopes and per-tool authorization
Authentication answers who presented the token. Authorization answers what that principal may do. Define scopes that match real capabilities, such as a read scope for listing records and a write scope for mutations. Check the required scope immediately before each sensitive operation.
You may protect an entire MCP server or leave public capabilities available while protecting selected tools. MCP Apps documentation demonstrates both per-server and per-tool patterns; treat that behavior as stack-specific and confirm that your SDK and client support it. Avoid a single broad scope when a destructive operation can be isolated behind a narrower permission.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Never pass an MCP token through blindly
A token issued for your MCP resource is not automatically a credential for a downstream API. Forwarding it can expose user authority to the wrong audience. If a tool calls another service, use a separate credential, a token exchange, or an intentionally delegated token whose audience and permissions were designed for that downstream service. Validate that downstream credential independently.
Reference implementation shape
Keep provider-specific verification behind one adapter so the MCP layer remains portable:
async function authenticate(request) {
const header = request.headers.get('authorization') || '';
if (!header.startsWith('Bearer ')) return { kind: 'challenge' };
const raw = header.slice(7);
const claims = await tokenVerifier.verify(raw); // provider JWKS or introspection
if (claims.iss !== EXPECTED_ISSUER) return { kind: 'invalid' };
if (claims.aud !== RESOURCE_ID) return { kind: 'invalid' };
if (claims.exp * 1000 < Date.now()) return { kind: 'invalid' };
return { kind: 'principal', subject: claims.sub, scopes: parseScopes(claims) };
}
async function handleMcp(request) {
const auth = await authenticate(request);
if (auth.kind === 'challenge') return challengeResponse();
if (auth.kind === 'invalid') return new Response('Invalid token', { status: 401 });
const needed = requiredScopeFor(request);
if (!auth.scopes.has(needed)) return new Response('Insufficient scope', { status: 403 });
return dispatchMcp(request, auth);
}
This is an enforcement shape, not a drop-in verifier: use your provider’s maintained JWT/JWKS or introspection library, key-cache behavior and clock-skew settings. Do not implement cryptographic verification with ad-hoc string parsing.
Testing checklist
- Metadata is reachable anonymously, returns valid JSON and names the canonical resource.
- The bearer challenge points to that metadata and uses the correct resource URL.
- Authorization and token requests include the resource parameter.
- PKCE S256 succeeds; unsupported or downgraded methods are rejected according to policy.
- CIMD works where supported, while DCR is retained only for clients that require it.
- A token from the right issuer but a different audience is rejected.
- Expired, revoked, malformed and tampered tokens never reach a tool.
- Each protected tool rejects missing scopes without leaking data.
- Provider key rotation, redirect URI mismatch and client re-registration produce actionable logs without secrets.
- Downstream calls use credentials intended for the downstream audience.
Troubleshooting common failures
Client never discovers authorization
Cause: metadata is at the wrong well-known URL, requires authentication, or contains an incorrect resource identifier. Fix: derive the URL from the exact protected path, serve it anonymously, validate JSON and compare the resource string byte-for-byte with the endpoint clients call.
Redirect URI mismatch
Cause: the registered URI differs by scheme, host, port, path or trailing slash. Fix: register the exact URI emitted by the client and avoid wildcard redirects in production.
PKCE or registration errors
Cause: the provider and client disagree about S256, CIMD or DCR support. Fix: inspect provider metadata, choose an explicitly supported method and label any DCR path as compatibility behavior.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
401 despite a recently issued token
Cause: wrong issuer, expired clock, stale JWKS cache, or audience/resource mismatch. Fix: inspect decoded claims in a secure diagnostic environment, refresh provider keys, synchronize clocks and verify the resource value used in both authorization and token requests.
403 on a tool that should work
Cause: the token is valid but lacks the operation’s required scope, or the server maps claim names incorrectly. Fix: document the required scope, normalize space-delimited scopes or provider permission claims, and test with a token intentionally carrying that permission.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsDownstream API rejects calls
Cause: an MCP audience token was forwarded to another service. Fix: obtain a downstream credential through that service’s supported delegation or token-exchange design.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Operations, reliability and cost
Cache provider discovery documents and JWKS keys with sensible refresh and rotation handling; do not cache authorization decisions beyond the token’s validity. Keep authorization middleware fast and observable, but redact bearer values and authorization codes from logs. Rate-limit metadata and token-error abuse separately from normal MCP traffic. At scale, introspection adds a network dependency, while local JWT verification adds key-rotation and revocation considerations; choose deliberately and monitor both latency and failure modes.
OAuth introduces provider, TLS, redirect and operational dependencies rather than a fixed MCP license cost. Budget for identity-provider usage, key management, monitoring and incident response. There is no universal MCP-client/identity-provider interoperability guarantee, so validate the exact combinations you publish as supported.
Or skip the browser setup
If your MCP server needs a screenshot capability, ScreenshotNeo provides a website screenshot API and MCP server. One GET request returns PNG, JPEG, WebP or PDF; it removes cookie-consent banners, newsletter popups and chat widgets before capture. Bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing result. Its MCP tools—take_screenshot, get_page_info and capture_pdf—let Claude, Cursor or another MCP client call the service directly.
Recommended Free Tools
Example cURL (see the ScreenshotNeo API documentation):
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
curl -G 'https://api.screenshotneo.com/v1/shot' -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get('https://api.screenshotneo.com/v1/shot', params={'access_key': 'YOUR_API_KEY', 'url': 'https://stripe.com'}, timeout=90)
open('shot.webp', 'wb').write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
The free plan includes 1,000 screenshots each month with no card. Paid plans start at $5 for 3,000 shots; every feature is available on every plan. Create a free ScreenshotNeo account.
Frequently Asked Questions
Does an MCP server need its own OAuth server?
No. The MCP server is the protected resource; a separate authorization server or identity provider can issue its tokens. Your service must still validate issuer, audience, expiry and permissions.
How does OAuth work with an MCP server over stdio?
The MCP authorization specification’s remote flow targets HTTP transports. Local stdio deployments generally use environment or embedded credentials, unless your application adds a separate local login design.
Should I use CIMD or Dynamic Client Registration?
Use CIMD when your client and provider support the current specification direction. Keep DCR for backward compatibility with clients or providers that require it, and test the exact combination.
Can I reuse the MCP access token for an API my tool calls?
Not by default. A token is audience-bound to the MCP resource. Obtain a downstream credential through an intentional delegation or token-exchange design.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

