Discovery
OAuth protected resource metadata (root alias for the MCP resource)
Root-path alias of the MCP protected-resource document.
Compatibility fallback for clients that probe the root /.well-known/oauth-protected-resource instead of following the 401's resource_metadata pointer (the documented Claude Code behaviour). Safe because this deployment has exactly one OAuth-protected resource, so the root and path-scoped documents are the same body.
Two acknowledged trades:
- RFC 9728 §3 says this well-known path corresponds to resource identifier {base} (no path), and §3.3 has clients validate resource against the resource they queried. This body claims resource={base}/mcp — a strict path-deriving validator would reject it, but Claude's fallback validates against the MCP server URL ({base}/mcp), which is exactly what the alias exists to satisfy. That is the intended trade.
- The alias squats the deployment's only root PRM slot: a future non-MCP protected resource at {base} cannot get its own root document without breaking this fallback. The mounted MCP app must re-confirm the "exactly one OAuth-protected resource" premise before adding one.
get/.well-known/oauth-protected-resource
Response
Successful Response
object required
Changes
Changed in 1 of the 114 revisions of this API.1
- ○
endpoint added
endpoint-added
- ○