OAuth discovery
The two metadata documents an MCP client reads first: the authorization server, which says where to authorize and register, and the protected resource, which says which authorization server guards the MCP endpoint. Both are public, need no token and are served at the root of the MCP host, without the /api prefix.
