OAuth protected-resource metadata for the default MCP surface
Returns the RFC 9728 path-scoped protected-resource metadata for the /mcp MCP surface, which is what its WWW-Authenticate challenge names on a 401. Identical to the origin-wide document except that resource names /mcp on this origin rather than the origin itself, so a client can check the document answers for the endpoint it called.
GET
/.well-known/oauth-protected-resource/mcpResponses
200
OAuth protected-resource discovery JSON scoped to /mcp.
object