@mcpcomp/core
The probe engine and check catalogue behind mcpcomp.
import { probeAuth, evaluateChecks, buildReport, diffReports } from "@mcpcomp/core";
const probe = await probeAuth("https://mcp.example.com/mcp");
const report = buildReport(probe, evaluateChecks(probe));
probeAuth performs unauthenticated discovery — Protected Resource Metadata,
the authorization-server ladder including the legacy fallback, and per-revision
protocol probing. evaluateChecks returns findings tagged MUST or SHOULD,
each citing the requirement it enforces. diffReports reports what changed
between two scans — the facts a verdict depends on, not the raw report.
Also exported: classifyReport (the doctor layer verdict — network, server,
identity provider, or inferred client state), formatDoctorReport,
registerMcpTools (serve the scanner as MCP tools on any transport), and the
Entra credential-expiry checker.
Protocol and OAuth semantics come from @modelcontextprotocol/client, so
verdicts match a real client's behaviour.
Apache-2.0.