Skip to content

OAuth 2.0 Protected Resource Metadata support #24

@hatasaki

Description

@hatasaki

According to MCP atuhorization specification 2025-06-18, supporting OAuth 2.0 Protected Resource Metadata becomes MUST.
https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization

Do you have a plan to add /.well-known/oauth-protected-resource endpoint to response resource metadata and to add the resource server endpoint info to WWW-Authenticate header of MCP API endpoints?

[example RFC9728]
HTTP/1.1 200 OK
Content-Type: application/json

{
"resource":
"https://resource.example.com",
"authorization_servers":
["https://as1.example.com",
"https://as2.example.net"],
"bearer_methods_supported":
["header", "body"],
"scopes_supported":
["profile", "email", "phone"],
"resource_documentation":
"https://resource.example.com/resource_documentation.html"
}

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions