Get protected resource metadata
GET/.well-known/oauth-protected-resource
Returns the RFC 9728 Protected Resource Metadata
document, naming the authorization server that guards /mcp. An unauthenticated request to
/mcp answers 401 with a WWW-Authenticate: Bearer resource_metadata="…" header pointing
here, which is how an OAuth-aware MCP client bootstraps the flow.
Responses
- 200
Protected resource metadata