auth fixture provides tools for creating test tokens, testing expiration, and validating scope enforcement.
Why Test Authentication?
Authentication tests verify that your server:- Rejects requests without valid tokens
- Accepts requests with valid tokens
- Enforces token expiration
- Validates token signatures
- Respects scope-based permissions
Creating Test Tokens
Theauth fixture generates real JWT tokens using RS256 signing:
Token Options
The default issuer is
https://test.frontmcp.local and the default audience is frontmcp-test. Override them with new TestTokenFactory({ issuer, audience }).
expiresIn is measured from now and rounded up to a whole second, so expiresIn: 1 gives a token that is valid for at least one full second and cannot expire before its first use.
Authenticating the client
mcp.authenticate(token) opens a new session for the token and rejects when the server refuses it, so an expired or badly signed token fails right there. After a rejection the client keeps its previous identity and session. On a client that is not connected yet it only stores the token for the next connect().
this.auth (for example this.auth.scopes), including in a server started by test.use().
Custom Claims
Add any custom claims your server needs:Pre-built Test Users
Theauth fixture includes pre-configured test users for common scenarios:
User Definitions
Testing Token Expiration
Expired Tokens
Short-Lived Tokens
Testing Invalid Tokens
Invalid Signature
Malformed Token
Testing Scope Enforcement
Scope-Based Access Control
Testing Multiple Scopes
JWKS Integration
For servers that verify tokens against JWKS endpoints:Testing Auth Modes
Public Mode (No Auth)
Local Mode (Auth Required)
Real-World Examples
Testing User Isolation
Testing Admin Operations
Best Practices
Do:- Test both positive (valid token) and negative (invalid/expired) cases
- Test scope enforcement for all protected operations
- Use pre-built test users for common scenarios
- Clean up created clients after multi-user tests
- Hard-code tokens in tests (always use
auth.createToken()) - Skip expiration testing
- Assume scopes are enforced without testing
- Forget to test anonymous access for public endpoints
MockOAuthServer
For integration testing of OAuth flows, useMockOAuthServer from @frontmcp/testing. It provides a fully functional OAuth 2.1 server with PKCE support.
Basic Usage
MockOAuthServerOptions
MockTestUser Interface
MockOAuthServerInfo Interface
Available Endpoints
Supported Grant Types
authorization_code- Standard OAuth flow with PKCErefresh_token- Refresh token rotationanonymous- Issue anonymous tokens for testing