netlify-mcp-servers-authentication

netlify-mcp-servers-authentication is a cursor rule for coding agents from netlify/context-and-tools. It costs 16 tokens per session (1,062 once invoked), scanned A, original, MIT.

A reference for protecting Netlify MCP servers, which let AI clients call connected tools and services. It describes shared-token authentication for one trusted user and separate API keys for multiple users.

In plain words
What is it for?
Use it when adding bearer-token checks to a Netlify MCP endpoint, choosing between one shared secret and per-user keys, or planning key creation, storage, rotation, and revocation.
Why use it?
It explains how to reject unauthorised requests and how to store API keys without keeping their plaintext versions. This helps prevent an exposed server from accepting arbitrary calls.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/netlify/context-and-tools/netlify-mcp-servers-authentication
Clone the repo
git clone --depth 1 https://github.com/netlify/context-and-tools

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for netlify-mcp-servers-authentication

README.md
[![agentmods](https://agentmods.dev/badge/rules/netlify/context-and-tools/netlify-mcp-servers-authentication.svg)](https://agentmods.dev/rules/netlify/context-and-tools/netlify-mcp-servers-authentication)
Your own site
<a href="https://agentmods.dev/rules/netlify/context-and-tools/netlify-mcp-servers-authentication"><img src="https://agentmods.dev/badge/rules/netlify/context-and-tools/netlify-mcp-servers-authentication.svg" alt="Measured on agentmods" height="20"></a>
Per session 16 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,062 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00016 $0.01062
Opus 5 $0.00008 $0.00531
Sonnet 5 $0.00003 $0.00212
Haiku 4.5 $0.00002 $0.00106

Measured 5d ago against content hash 81a390ca9085, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

netlify-mcp-servers-authentication scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

cursor/rules/netlify-mcp-servers-authentication.mdc · 89 lines

How it starts

The opening of the file, as written. The whole thing — 89 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MCP Server Authentication

Two models. Pick based on who calls the server. Both put Authorization: Bearer <token> on every request and 401 anything that fails.

Model 1 — single shared secret (personal / single-user)

One token in an env var, compared in constant time. This is the whole thing — see checkBearer in the main SKILL. Generate with openssl rand -hex 32, store as a secret env var, hand the same token to your one client. To rotate or revoke: set a new value and update the client.

Use this when the server is just for you (or one trusted script). Don't reach for anything heavier than this until you actually have multiple users.

Model 2 — per-user API keys (multi-user)

Each person authenticates as themselves with their own revocable key. Netlify Identity protects a web UI where users mint keys; the MCP endpoint itself is authenticated by the key, not by an Identity session (agents have no browser cookie). The two systems are separate on purpose.

Store keys in Netlify Database. The essential rules:

  • Never store the plaintext key. Store a SHA-256 hash plus a short non-secret prefix for display.
  • Show the plaintext exactly once, at creation. If the user loses it, they mint a new one.
  • Tie each key to a user and support revocation (soft-delete) so a leaked key is killable without touching others.

A workable row shape:

api_keys
  id          uuid
  user_email  text        -- who this key acts as
  label       text        -- "laptop", "ci", etc.
  prefix      text        -- first ~11 chars, safe to display
  key_hash    text unique -- sha256(plaintext), hex
  created_at  timestamptz
  last_used_at timestamptz
  revoked_at  timestamptz -- null = active

Generate

import { createHash, randomBytes } from "node:crypto";

export function generateApiKey() {
  const plaintext = `mk_${randomBytes(24).toString("base64url")}`;
  return {
    plaintext,                                   // return to the user ONCE
    prefix: plaintext.slice(0, 11),              // store + display
    keyHash: createHash("sha256").update(plaintext).digest("hex"), // store
  };
}

Read the full file on GitHub · 89 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 89 lines · 16 tokens per session scan A 81a390ca9085

Subscribe to this mod's changes

netlify-mcp-servers-authentication is a cursor rule published in the GitHub repository netlify/context-and-tools (36 stars, last pushed today), licensed MIT. It adds 16 tokens to every session and 1,062 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.