OAuth 2.0 Protected Resource Metadata (RFC 9728)
Public discovery document advertising the authorization server that protects the per-organization MCP endpoint, so spec-compliant MCP clients can complete an OAuth flow without manual configuration. The advertised resource is the per-org URI <APP_URL>/api/mcp/o/{org}, which tokens are audience-bound to (RFC 8707).
GET
/.well-known/oauth-protected-resource/api/mcp/o/{org}better-auth.session_token<token>
Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Path Parameters
org*string
Organization id (uuid). Identifies the organization this MCP endpoint is bound to.
curl -X GET "https://your-instance/.well-known/oauth-protected-resource/api/mcp/o/string"{
"resource": "http://example.com",
"authorization_servers": [
"http://example.com"
],
"scopes_supported": [
"string"
],
"bearer_methods_supported": [
"string"
],
"resource_documentation": "http://example.com"
}