---
title: "OAuth authorization server metadata for the MCP resource"
method: GET
path: "/.well-known/oauth-authorization-server/mcp"
tags: ["Discovery"]
---

# OAuth authorization server metadata for the MCP resource

`GET /.well-known/oauth-authorization-server/mcp`

RFC 8414 metadata for the path-scoped issuer `{base}/mcp`.

RFC 8414 §3.1 path insertion: this is the metadata URL clients derive for
the issuer `{base}/mcp` named by the protected-resource document. It
advertises the anonymous OAuth-client registration door (`/oauth-clients`)
and the public-client profile (`none` + PKCE S256) — the root document is a
separate, unchanged surface whose `registration_endpoint` remains the agent
`/register`.

## Response `200`

Successful Response

- object

## Other responses

- `400` — Bad Request
- `404` — Interactive OAuth for MCP is disabled (`server.mcp.oauth.enabled=false`): the route answers the framework's plain route-not-found 404, so the gate state is unobservable.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-02** `df1a610a7ed8` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/.well-known/oauth-authorization-server/mcp/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
