---
title: "OAuth protected resource metadata for the MCP resource"
method: GET
path: "/.well-known/oauth-protected-resource/mcp"
tags: ["Discovery"]
---

# OAuth protected resource metadata for the MCP resource

`GET /.well-known/oauth-protected-resource/mcp`

RFC 9728 protected-resource metadata for `{base}/mcp`.

Names the /mcp-scoped authorization server and the MCP tool scopes. The
same body is also served at the root well-known path for clients that
ignore the 401's `resource_metadata` pointer.

## Response `200`

Successful Response

- object

## Other responses

- `400` — Bad Request
- `404` — Interactive OAuth for MCP is disabled (`server.mcp.oauth.enabled=false`): the route answers the framework's plain route-not-found 404, so the gate state is unobservable.
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-02** `df1a610a7ed8` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/.well-known/oauth-protected-resource/mcp/get.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc.dev/jentic/apis/jentic-control-plane-api/revisions/e4688b93dfc7?raw)
