Protected Resource
oauth
Protected Resource
RFC 9728 protected-resource metadata. The protected resource is the MCP endpoint
(<origin>/mcp — the thing whose 401 WWW-Authenticate points here), NOT /api/v1.
Served at BOTH the bare path and the /mcp-suffixed one: spec clients append the
resource’s path to the well-known prefix, and the app mount at /mcp means the SDK’s
own metadata route lands under /mcp/… where nothing looks — so we serve it at root.
GET
Protected Resource
Response
200 - application/json
Successful Response
The response is of type Response Protected Resource Well Known Oauth Protected Resource Mcp Get · object.