---
title: "OAuth protected resource metadata (root alias for the MCP resource)"
method: GET
path: "/.well-known/oauth-protected-resource"
tags: ["Discovery"]
---

# OAuth protected resource metadata (root alias for the MCP resource)

`GET /.well-known/oauth-protected-resource`

Root-path alias of the MCP protected-resource document.

Compatibility fallback for clients that probe the root
`/.well-known/oauth-protected-resource` instead of following the 401's
`resource_metadata` pointer (the documented Claude Code behaviour). Safe
because this deployment has exactly one OAuth-protected resource, so the
root and path-scoped documents are the same body.

Two acknowledged trades:

- RFC 9728 §3 says this well-known path corresponds to resource identifier
  ``{base}`` (no path), and §3.3 has clients validate ``resource`` against
  the resource they queried. This body claims ``resource={base}/mcp`` — a
  strict path-deriving validator would reject it, but Claude's fallback
  validates against the MCP server URL (``{base}/mcp``), which is exactly
  what the alias exists to satisfy. That is the intended trade.
- The alias squats the deployment's only root PRM slot: a future non-MCP
  protected resource at ``{base}`` cannot get its own root document
  without breaking this fallback. The mounted MCP app must re-confirm the
  "exactly one OAuth-protected resource" premise before adding one.

## Response `200`

Successful Response

- object

## Other responses

- `400` — Bad Request
- `404` — Interactive OAuth for MCP is disabled (`server.mcp.oauth.enabled=false`): the route answers the framework's plain route-not-found 404, so the gate state is unobservable.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-02** `df1a610a7ed8` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/.well-known/oauth-protected-resource/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
