Skip to main content

ProtectedResourceMetadata

RFC 9728 protected-resource metadata, returned bare rather than enveloped.

resourcestring

The protected resource's identifier — the public URL of the MCP endpoint.

Example: https://api.service.app.uysot.uz/v1/mcp
authorization_serversstring[]

Authorization servers that issue tokens for this resource.

Example: ["https://api.service.app.uysot.uz"]
scopes_supportedstring[]
Example: ["PERMISSION_OPEN_API_MCP:READ"]
bearer_methods_supportedstring[]

Always header — the token goes in Authorization: Bearer.

Example: ["header"]
ProtectedResourceMetadata
{
"resource": "https://api.service.app.uysot.uz/v1/mcp",
"authorization_servers": [
"https://api.service.app.uysot.uz"
],
"scopes_supported": [
"PERMISSION_OPEN_API_MCP:READ"
],
"bearer_methods_supported": [
"header"
]
}