OAuth Protected Resource metadata

RFC 9728 metadata tells agents which authorization servers protect a resource.

Standard
Recommended

What it checks

The extension fetches /.well-known/oauth-protected-resource, the location RFC 9728 defines for metadata about a protected resource. It passes when the response is successful, non-empty, and JSON: the Content-Type mentions json, or the body starts with { or [. The fields inside are not validated.

Results

Status When
Pass /.well-known/oauth-protected-resource returns a JSON document
N/A The path is missing or does not return JSON

How to fix

If your API requires authorization, publish metadata on the API’s origin that names the resource and the authorization servers that issue tokens for it:

{
  "resource": "https://api.example.com",
  "authorization_servers": ["https://auth.example.com"]
}

An agent that gets a 401 from your API can then find where to authorise without prior configuration. MCP clients use this document for the same purpose.

Related: OAuth Authorization Server discovery.