Protected Resource Metadata
GET/.well-known/oauth-protected-resource
RFC 9728 protected-resource metadata. An MCP client reaches this document from the
WWW-Authenticate header of a 401 on POST /v1/mcp, and learns from it which
authorization server guards the resource.
Clients that append the resource path
(/.well-known/oauth-protected-resource/v1/mcp, RFC 9728 §3.1) get the same document.
The single advertised scope, PERMISSION_OPEN_API_MCP:READ, opens the MCP endpoint as a
whole. What the connected employee can actually see through it is decided per tool by
their own permissions in the core service, not by this scope.
Requires no token.
Responses
- 200
The protected resource metadata document.