protected-resource-metadata
Installation
SKILL.md
Protected Resource Metadata for MCP Servers
Security Requirement
MCP servers MUST implement OAuth 2.0 Protected Resource Metadata (RFC 9728). MCP clients MUST use this metadata to discover the authorized authorization servers for a given MCP server.
What It Provides
Protected Resource Metadata allows MCP clients to discover:
- Which authorization servers are trusted by the MCP server
- What scopes are available (
scopes_supported) - What token formats and mechanisms are required