Authorization Server Metadata
GET/.well-known/oauth-authorization-server
RFC 8414 authorization-server metadata — where to authorize, exchange tokens, revoke and register. A client reads this before it holds any credential, so the endpoint is open and the document is returned bare, not in the standard envelope.
Clients that append the resource path (/.well-known/oauth-authorization-server/v1/mcp,
RFC 8414 §3.1) get the same document; this deployment serves one authorization server for
every resource.
authorization_endpoint is the consent page — a browser URL — not
GET /v1/open-api/oauth/authorize, which is the API that page calls.
registration_endpoint is present only while dynamic registration is enabled.
scopes_supported deliberately advertises only PERMISSION_OPEN_API_MCP:READ. Some
clients copy every advertised scope into their authorization request, and a dynamically
registered client can never hold more than that one grant — advertising the full
permission matrix here would make every such request fail. Applications registered
through the Uysot UI are unaffected: they send their own scope and never read it from
this document.
Requires no token.
Responses
- 200
The authorization server metadata document.