Skip to main content

Authorization Server Metadata

GET 

/.well-known/oauth-authorization-server

RFC 8414 authorization-server metadata — where to authorize, exchange tokens, revoke and register. A client reads this before it holds any credential, so the endpoint is open and the document is returned bare, not in the standard envelope.

Clients that append the resource path (/.well-known/oauth-authorization-server/v1/mcp, RFC 8414 §3.1) get the same document; this deployment serves one authorization server for every resource.

authorization_endpoint is the consent page — a browser URL — not GET /v1/open-api/oauth/authorize, which is the API that page calls. registration_endpoint is present only while dynamic registration is enabled.

scopes_supported deliberately advertises only PERMISSION_OPEN_API_MCP:READ. Some clients copy every advertised scope into their authorization request, and a dynamically registered client can never hold more than that one grant — advertising the full permission matrix here would make every such request fail. Applications registered through the Uysot UI are unaffected: they send their own scope and never read it from this document.

Requires no token.

Responses​

The authorization server metadata document.