Spring-ai MCP Security — Security skill for Claude Code
Authorization framework for MCP client/server using Spring Security.
How to install Spring-ai MCP Security
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open spring-ai-community/mcp-security and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Spring-ai MCP Security does
[](https://opensource.org/licenses/Apache-2.0) [](https://www.oracle.com/java/technologies/javase/jdk17-archive-downloads.html)
Alternatives in Security
- Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
- Cve MCP Server — Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco 1.2k ★
README
MCP Security
[](https://opensource.org/licenses/Apache-2.0) [](https://www.oracle.com/java/technologies/javase/jdk17-archive-downloads.html)
Security and Authorization support for Model Context Protocol in Spring AI.
⚠️ Versions 0.1.x of `mcp-security` only work Spring AI's 2.0.x branch. For Spring AI 1.1.x, use version `0.0.6`.
Table of Contents
- Overview
- MCP Server Security
- MCP Client Security
- Authorization Server
- Samples
- Integrations (Cursor, Claude Desktop, ...)
- License
Overview
This repository provides [Authorization](https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization) support for Spring AI integrations with the Model Context Protocol (MCP). It covers both MCP Clients, MCP Servers, and Spring Authorization Server.
The project enables developers to:
- Secure MCP servers with OAuth 2.0 authentication
- Configure MCP clients with OAuth 2.0 authorization flows
- Set up authorization servers specifically designed for MCP workflows
- Implement fine-grained access control for MCP tools and resources
MCP Server Security
Provides OAuth 2.0 resource server capabilities for [Spring AI's MCP servers](https://docs.spring.io/spring-ai/reference/api/mcp/mcp-server-boot-starter-docs.html). It also provides basic support for API-key based servers. This module is compatible with Spring WebMVC-based servers only.
Quick start with `mcp-server-security-spring-boot` (recommended)
The easiest way to add OAuth2 security to your MCP server is with the Boot auto-configuration module. It provides a default `SecurityFilterChain` that secures all endpoints, with no additional configuration required beyond setting the issuer URI.
*Maven*
org.springaicommunity
mcp-server-security-spring-boot
0.1.6
...
Related Skills
Security Audit Web App
Use when auditing a web app frontend/edge layer for common security mistakes — server vs client boundary leaks
6.3 Performance
Kjør kun performance-audit på prosjektet. Sjekker bundle-størrelse, Server/Client-balanse, caching, bilder/fon
Claude Code For Jetbrains
Claude Code for JetBrains IDEs — a native GUI client for Anthropic's AI coding agent. Streaming chat, editable
Claude Code Native
Claude Code for JetBrains IDEs — a native GUI client for Anthropic's AI coding agent. Streaming chat, editable
AWS MCP Server
by alexei-led - Features multiple Python environment setup options with detailed code style guidelines, compre
Firewalla MCP Server
Firewalla MCP Server - Claude integration for network security monitoring and firewall management
Related Agents
Ehs AI Safety
AI, agent and chatbot security specialist for the Ethical Hacker Squad. Reviews the instruction/data boundary,
Airlock Worker
Default Airlock worker — implement, refactor, debug, and test the embeddable device-authorization core (RFC 86
Council Haiku
Council seat - black box. Walks the Profile's Client path as a client would, using the Browser MCP server only