Skip to main content

Protected Resource Metadata

GET 

/.well-known/oauth-protected-resource

RFC 9728 protected-resource metadata. An MCP client reaches this document from the WWW-Authenticate header of a 401 on POST /v1/mcp, and learns from it which authorization server guards the resource.

Clients that append the resource path (/.well-known/oauth-protected-resource/v1/mcp, RFC 9728 §3.1) get the same document.

The single advertised scope, PERMISSION_OPEN_API_MCP:READ, opens the MCP endpoint as a whole. What the connected employee can actually see through it is decided per tool by their own permissions in the core service, not by this scope.

Requires no token.

Responses​

The protected resource metadata document.