---
title: "OAuth Protected Resource metadata · Sitebulb Labs"
description: "RFC 9728 metadata tells agents which authorization servers protect a resource."
url: https://labs.sitebulb.com/docs/checks/protocol-discovery/oauth-protected-resource/
---

# OAuth Protected Resource metadata

RFC 9728 metadata tells agents which authorization servers protect a resource.

- Category

  [Protocol discovery](https://labs.sitebulb.com/docs/checks/protocol-discovery)

- Standard

  Recommended

## What it checks

The extension fetches `/.well-known/oauth-protected-resource`, the location RFC 9728 defines for metadata about a protected resource. It passes when the response is successful, non-empty, and JSON: the `Content-Type` mentions `json`, or the body starts with `{` or `[`. The fields inside are not validated.

## Results

| Status   | When                                                            |
| -------- | --------------------------------------------------------------- |
| **Pass** | `/.well-known/oauth-protected-resource` returns a JSON document |
| **N/A**  | The path is missing or does not return JSON                     |

## How to fix

If your API requires authorization, publish metadata on the API’s origin that names the resource and the authorization servers that issue tokens for it:

```json
{
  "resource": "https://api.example.com",
  "authorization_servers": ["https://auth.example.com"]
}
```

An agent that gets a `401` from your API can then find where to authorise without prior configuration. MCP clients use this document for the same purpose.

Related: [OAuth Authorization Server discovery](https://labs.sitebulb.com/docs/checks/protocol-discovery/oauth-discovery).
