spring-ai-community

Spring-ai MCP Security — Security skill for Claude Code

Security community intermediate

Authorization framework for MCP client/server using Spring Security.

How to install Spring-ai MCP Security

This entry records only its repository, not the path inside it, so there is no exact command to give. Open spring-ai-community/mcp-security and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Spring-ai MCP Security does

[](https://opensource.org/licenses/Apache-2.0) [](https://www.oracle.com/java/technologies/javase/jdk17-archive-downloads.html)

Alternatives in Security

  • Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
  • Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
  • Cve MCP Server — Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco 1.2k ★

README

MCP Security

[](https://opensource.org/licenses/Apache-2.0) [](https://www.oracle.com/java/technologies/javase/jdk17-archive-downloads.html)

Security and Authorization support for Model Context Protocol in Spring AI.

⚠️ Versions 0.1.x of `mcp-security` only work Spring AI's 2.0.x branch. For Spring AI 1.1.x, use version `0.0.6`.

Table of Contents

Overview

This repository provides [Authorization](https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization) support for Spring AI integrations with the Model Context Protocol (MCP). It covers both MCP Clients, MCP Servers, and Spring Authorization Server.

The project enables developers to:

  • Secure MCP servers with OAuth 2.0 authentication
  • Configure MCP clients with OAuth 2.0 authorization flows
  • Set up authorization servers specifically designed for MCP workflows
  • Implement fine-grained access control for MCP tools and resources

MCP Server Security

Provides OAuth 2.0 resource server capabilities for [Spring AI's MCP servers](https://docs.spring.io/spring-ai/reference/api/mcp/mcp-server-boot-starter-docs.html). It also provides basic support for API-key based servers. This module is compatible with Spring WebMVC-based servers only.

Quick start with `mcp-server-security-spring-boot` (recommended)

The easiest way to add OAuth2 security to your MCP server is with the Boot auto-configuration module. It provides a default `SecurityFilterChain` that secures all endpoints, with no additional configuration required beyond setting the issuer URI.

*Maven*


        org.springaicommunity
        mcp-server-security-spring-boot
        0.1.6

...