
Auth Sentinel
Audits SAML and OpenID Connect SSO setups so misconfigured identity flows do not become production auth incidents.
Overview
Auth-Sentinel is a MCP server for the Ship phase that audits SAML and OpenID SSO identity configurations to reduce auth misconfiguration risk.
What is this MCP server?
- Auth-Sentinel MCP remote focused on SSO identity configuration auditing
- Covers SAML and OpenID-related posture via hosted SSE at auth-sentinel-mcp.vercel.app
- MCP 2025-12-11 server schema, version 1.0.0
- Optional EIP-3009 payment-signature for premium settlement paths
- Complements manual pentests by targeting IdP and OIDC wiring mistakes
- 1 SSE remote endpoint
- Targets SAML and OpenID identity auditing per server description
What problem does it solve?
Misconfigured SSO and OIDC settings are easy to ship under time pressure and painful to debug when enterprise customers cannot log in.
Who is it for?
Solo B2B SaaS builders enabling SAML or OIDC for their first team customers who want agent-driven SSO reviews without a dedicated identity engineer.
Skip if: Consumer apps with only email-password auth and no federation plans.
What do I get? / Deliverables
After you add the remote MCP server, your agent can run identity-configuration audits that surface SAML and OpenID issues to fix before go-live.
- SSO and OpenID configuration audit output via MCP
- Actionable identity hardening notes for ship security checklist
- Agent workflow hook for pre-release federation reviews
Recommended MCP Servers
Journey fit
How it compares
MCP SSO configuration auditor, not an identity provider product or generic OWASP scanner skill.
Common Questions / FAQ
Who is Auth Sentinel for?
Indie and small-team SaaS founders implementing SAML or OpenID Connect who need MCP tooling to review identity configs before production.
When should I use Auth Sentinel?
Use it during Ship security when SSO is staged or just enabled, or before a security questionnaire asks about federation controls.
How do I add Auth Sentinel to my agent?
Configure https://auth-sentinel-mcp.vercel.app/api/mcp as an SSE remote MCP server; supply payment-signature only if required for premium tiers.