NOIR
Capabilities

Connections and access

Add exact-owner OAuth, OpenAPI, MCP, encrypted secrets, scoped API keys, or a public MCP surface.

A static connector is configured once by the application. A dynamic connection lets an authenticated user connect their own provider account. Choose static configuration unless the product genuinely needs per-user authorization.

Dynamic connection lifecycle

@noir-agent/agent/connections provides definitions, owner-scoped stores, projection, and connectionsCapability(). A connection record contains status and provider metadata, never plaintext credentials.

The provider owns connect URL creation, callback handling, refresh, health, reauthorization, and bounded calls. Model tools can request a configured connection or operation; they cannot choose OAuth endpoints, credential headers, owners, or unreviewed operations.

MCP connections

@noir-agent/agent/connections/mcp uses the official MCP SDK for exact-owner OAuth and pinned remote tools. dynamicMcpConnectionProvider() supports RFC 9728 discovery, dynamic client registration, PKCE S256, code exchange, refresh, invalidation, and host-owned elicitation.

Every call fetches a fresh bounded tool catalog and rejects a missing or changed allowlisted schema. Results are projected, secret-scrubbed, and byte-bounded.

OpenAPI connections

@noir-agent/agent/connections/openapi loads a developer-pinned HTTPS specification and verifies the OpenAPI version, base server, security scheme, operation, method, path, parameters, request body, success response, and inline schemas before a call.

Specification retrieval is credential-free. The exact-owner API key or bearer token is attached only to the pinned operation endpoint. Unresolved schema references and unreviewed redirects are rejected.

Encrypted secrets

@noir-agent/agent/secrets stores encrypted provider material under an exact owner. Memory and Postgres stores expose metadata for listing but return decrypted values only through an authorized resolution path. Conflicts, decryption failures, and limit errors are distinct.

Keys for encrypting the secret store belong to deployment configuration. Do not store them in the same database as encrypted records.

Scoped API keys

@noir-agent/agent/api-keys issues a 256-bit key once, then persists only a versioned hash, prefix, scopes, expiry, revocation, rotation lineage, and last-used time. Verification is constant-time and owner-scoped. Rotation can overlap safely without revealing the prior plaintext.

Use these keys for your own self-hosted API surface, not provider credentials.

Expose tools as MCP

@noir-agent/agent/mcp-server provides a stateless Streamable HTTP handler and an optional self-hosted OAuth 2.1 authorization service. Create a fresh server and transport per request. Bearer authentication resolves an exact owner; non-read tools also require the host’s authorizeTool decision.

Mount only the documented /mcp, well-known, and /oauth/* routes. OAuth supports discovery, policy-gated client registration, exact redirect matching, resource audiences, PKCE S256, hashed single-use codes, rotating refresh tokens with replay-family revocation, owner rechecks, and token revocation.

Cleanup is explicit and bounded. Invoke purge operations from your scheduler; the module starts no hidden timer.

Choose the surface

RequirementUse
one application-owned provider accountstatic connector
one provider account per userdynamic connection
remote MCP with OAuthMCP connection provider
reviewed REST operationOpenAPI connection provider
encrypted provider materialsecret store
credentials for your own APIAPI-key store
expose selected tools to MCP clientsMCP server

Verify

Test owner mismatch, OAuth state replay, PKCE failure, refresh rotation, schema drift, private DNS resolution, cross-origin redirect, secret-key rotation, expired API keys, write-tool denial, and duplicate authorization-code exchange.

On this page