Oauth Authorization Server Aggregate
OAuth authorization server discovery for the aggregate /mcp endpoint, the RFC 8414 path-inserted form for a client that treats {base}/mcp as its authorization base URL.
The single-segment /mcp is reserved for the aggregate so the discovery chain stays consistent: the aggregate protected-resource document advertises {base}/mcp as its authorization server, so the document served here must have issuer {base}/mcp. A server literally named mcp therefore does not take this route; it keeps its standard two-segment discovery at /.well-known/oauth-authorization-server/mcp/mcp. Letting the per-server row win here instead would serve an issuer of {base} against a resource that advertised {base}/mcp, which fails the RFC 8414 issuer check and breaks the front door.
Response
Successful Response
Changes
Changed in 8 of the 42 revisions of this API.15
- ○
api tag
mcp_byok_oauthaddedapi-tag-added
- ○
api tag
mcpremovedapi-tag-removed
- ○
- ○
api tag
mcpaddedapi-tag-added
- ○
api tag
mcp_byok_oauthremovedapi-tag-removed
- ○
- ○
api tag
mcp_byok_oauthaddedapi-tag-added
- ○
api tag
mcpremovedapi-tag-removed
- ○
- ○
api tag
mcpaddedapi-tag-added
- ○
api tag
mcp_byok_oauthremovedapi-tag-removed
- ○
- ○
api tag
mcp_byok_oauthaddedapi-tag-added
- ○
api tag
mcpremovedapi-tag-removed
- ○
- ○
api tag
mcpaddedapi-tag-added
- ○
api tag
mcp_byok_oauthremovedapi-tag-removed
- ○
- ○
api tag
mcp_byok_oauthaddedapi-tag-added
- ○
api tag
mcpremovedapi-tag-removed
- ○
- ○
endpoint added
endpoint-added
This revision also has 5 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog
- ○