OAuth Protected Resource metadata
RFC 9728 metadata tells agents which authorization servers protect a resource.
- Category
- Protocol discovery
- Standard
- Recommended
What it checks
The extension fetches /.well-known/oauth-protected-resource, the location RFC
9728 defines for metadata about a protected resource. It passes when the
response is successful, non-empty, and JSON: the Content-Type mentions
json, or the body starts with { or [. The fields inside are not
validated.
Results
| Status | When |
|---|---|
| Pass | /.well-known/oauth-protected-resource returns a JSON document |
| N/A | The path is missing or does not return JSON |
How to fix
If your API requires authorization, publish metadata on the API’s origin that names the resource and the authorization servers that issue tokens for it:
{
"resource": "https://api.example.com",
"authorization_servers": ["https://auth.example.com"]
}
An agent that gets a 401 from your API can then find where to authorise
without prior configuration. MCP clients use this document for the same
purpose.
Related: OAuth Authorization Server discovery.