OAuth 2.0 Protected Resource Metadata (RFC 9728)

Public discovery document advertising the authorization server that protects the per-organization MCP endpoint, so spec-compliant MCP clients can complete an OAuth flow without manual configuration. The advertised resource is the per-org URI <APP_URL>/api/mcp/o/{org}, which tokens are audience-bound to (RFC 8707).

GET/.well-known/oauth-protected-resource/api/mcp/o/{org}

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Path Parameters

org*string

Organization id (uuid). Identifies the organization this MCP endpoint is bound to.

curl -X GET "https://your-instance/.well-known/oauth-protected-resource/api/mcp/o/string"
{
  "resource": "http://example.com",
  "authorization_servers": [
    "http://example.com"
  ],
  "scopes_supported": [
    "string"
  ],
  "bearer_methods_supported": [
    "string"
  ],
  "resource_documentation": "http://example.com"
}