MCP serverio.github.michal-lefler/secure-flows
MCP server for secureFlows (secure-flows.com).
Read more
MCP server for secureFlows (secure-flows.com). Alias of io.github.michal-lefler/secureflows-mcp.Overview
Score?
UNRATED 0.672
of what a free look can see, on 30 looks
Looks
35
last 16 hr ago
Tools
18
changed 3 days ago
More info
URL
www.secure-flows.com/mcp?alias=secure-flows
streamable-http
Says it is
secureflows 0.2.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.672 · highest on record 0.8561
Toolsfrom sha256:e687cc6dc0…caf945 · +0 −0 3 days ago
| Tool | Schema |
|---|---|
| auth_session_callback **Browser redirect endpoint** used after hosted `/app/sessions/login`. No `Authorization` header.
1. Verifies **`firebaseToken`** (Firebase ID token).
2. Ensures **`client_redirec |
input · no output |
| delete_sessions_delete_key Removes `key` from the session payload and returns `true` if the key existed.
Source: DELETE /api/v1/sessions/delete/{key}
Requires `auth.sessionToken` and forwards it as a Bearer |
input · no output |
| get_auth_logout Browser-friendly logout endpoint for **cross-site** clients (e.g. apps running on `localhost`).
Use this as a **top-level navigation** (not XHR/fetch) so `Clear-Site-Data` is appl |
input · no output |
| get_docs_search Embeds the query with Ollama (`nomic-embed-text`) and returns the closest public doc chunks
from the environment's search index (pgvector).
Source: GET /api/v1/docs/search
No Auth |
input · no output |
| get_sessions Returns the decrypted session payload for the authenticated internal session token.
Response shape is a **flat JSON object**. Empty payload returns `{}`.
Source: GET /api/v1/sess |
input · no output |
| get_sessions_get_key Retrieves the decrypted payload value for `key`.
**Important:** `404` means the key was never written (normal first-use case). Do not treat as an error.
Source: GET /api/v1/sessi |
input · no output |
| get_sessions_identity Returns the workspace end-user's **`userId`** and **email** for the authenticated session
token. Does not return Firebase UID or session payload.
`userId` is a stable, opaque iden |
input · no output |
| get_sessions_my Returns a page of sessions for the current user within the current workspace.
Self-service dashboard endpoint — requires workspace **`enableSelfService: true`**.
Payload is include |
input · no output |
| post_auth_logout Logs out the current session **without revoking** it.
**Browser warning:** calling this endpoint via XHR/fetch from a different origin than `secure-flows.com`
is not a reliable wa |
input · no output |
| post_sessions Verifies **Firebase** ID token, creates a session for **`workspaceName`**, stores serialized
**`payload`** (defaults to `{}` when omitted), and returns **`sessionToken`** (JWT; sub |
input · no output |
| post_sessions_get_or_create Verifies **Firebase** ID token. If an **active** session already exists for
**`(workspaceName, Firebase UID, app_id)`**, returns a new **`sessionToken`** JWT for the **most
recentl |
input · no output |
| post_sessions_renew_session_token Verifies **Firebase** ID token. Parses **`sessionToken`** path segment as an internal SESSION JWT **without
enforcing JWT expiry** (signature and `tokenType=SESSION` are still vali |
input · no output |
| post_sessions_revoke Permanently revokes the session referenced by the internal SESSION Bearer token. The session ends and everything stored in it is destroyed and cannot be restored. This is NOT sign- |
input · no output |
| post_sessions_revoke_session_id Self-service dashboard endpoint. Revokes a session owned by the caller in the current workspace.
The session ends and its stored data is destroyed permanently; this is not sign-out |
input · no output |
| post_sessions_set_key Sets a key in the encrypted session payload and returns the updated decrypted payload. If the JSON body is `{ "value": <x> }`, the server unwraps it and stores `<x>` directly.
Sou |
input · no output |
| secureflows_build_login_url Builds a correct hosted-login redirect URL. Needs no secureFlows token — safe to call at app-scaffolding time,
before any user session exists, which is the phase most secureFlows i |
input · no output |
| secureflows_build_logout_url Builds a correct redirect-logout URL and refuses to build one that violates the two documented logout anti-patterns:
a redirect_uri pointing at /callback (SPA callback handlers tre |
input · no output |
| secureflows_lint_integration Checks source you already generated against the secureFlows integration rules. Needs no secureFlows token; safe at
scaffolding time. Pass every auth/session-related file in one cal |
input · no output |
Verify it yourself
npx teppi-check https://www.secure-flows.com/mcp?alias=secure-flowscurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2JB4JQRSK458BKFPWSD0