Enterprise DNA Enterprise DNA
M MCP Servers Developer low

apatureai/bastion

by Various

A remote MCP server for in-loop design review, and a worked reference for OAuth 2.1 auth, SSRF-safe URL handling, and long-running jobs over MCP.

MCP

apatureai/bastion

Added 13 Sept 2026

#ai-agents #design-review #mcp #mcp-server #model-context-protocol #oauth2 #ssrf #typescript

Overview

A remote MCP server that supports in-loop design review, and also serves as a worked reference for OAuth 2.1 authentication, SSRF-safe URL handling, and long-running jobs over MCP. It is written in TypeScript and intended as both a usable tool and a learning resource.

Best for

Best for
Developers building MCP servers who need reference implementations for auth, security, and long-running tasks

Use cases

  • Integrate design review into an MCP-based workflow
  • Reference OAuth 2.1 patterns for MCP server authentication
  • Model SSRF-safe URL handling and long-running job patterns

How to use

Tools exposed

  • design_review
  • design_review_get
  • design_recheck
  • design_review_cancel
  • design_review_panel_action

Tested with

Claude Code, Cursor, VS Code, ChatGPT

Notes

A remote MCP server that supports in-loop design review, and also serves as a worked reference for OAuth 2.1 authentication, SSRF-safe URL handling, and long-running jobs over MCP. It is written in TypeScript and intended as both a usable tool and a learning resource.

1 stars on GitHub. Last updated 2026-09-07. Licensed MIT.

Use cases

  • Integrate design review into an MCP-based workflow
  • Reference OAuth 2.1 patterns for MCP server authentication
  • Model SSRF-safe URL handling and long-running job patterns

Pros

  • Serves as a concrete reference for OAuth 2.1 and SSRF-safe URL handling
  • Written in TypeScript, matching many MCP tooling stacks
  • Addresses long-running jobs, a common MCP production concern

Cons

  • Very early stage with only 1 star and minimal adoption
  • Scope is narrow, focused on design review and reference patterns
  • No evidence of production readiness or active maintenance

Indexed from awesome-mcp-servers-punkpeye and enriched against its public facts.

Pros

  • Serves as a concrete reference for OAuth 2.1 and SSRF-safe URL handling
  • Written in TypeScript, matching many MCP tooling stacks
  • Addresses long-running jobs, a common MCP production concern

Cons

  • Very early stage with only 1 star and minimal adoption
  • Scope is narrow, focused on design review and reference patterns
  • No evidence of production readiness or active maintenance

Pairs with

Other entries in the index that connect to this one. Click through to see the chain.

Free 27-page guide

Get the free Developer’s Field Guide

A 27-page field guide to the AI coding workflow with Claude. Claude Code, MCP servers, the prompt patterns that work, and what to delegate. Free.

Enter your work email. We send it straight over, plus a few short notes worth knowing. Unsubscribe any time.

No spam. Unsubscribe any time.

Running a business, not writing the code? See the MCP servers picked for operators, and get your first one wired up with us.

Operator picks