> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://api.docs.modulards.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server.

# Retrieve the authorization server metadata

GET https://api.modulards.com/.well-known/oauth-authorization-server

Returns the OAuth authorization server metadata (RFC 8414) of Modular DS: the issuer, the authorization, token and registration endpoints, and what the server supports. An MCP client reads it to learn where to send the user to authorize and where to register.

The server supports the authorization code flow with PKCE (`S256`) and refresh tokens, and advertises the scopes `mcp:use` and `offline_access`. Asking for any other scope makes the authorization request fail with `invalid_scope`.

Public, served at the root of the MCP host, without the `/api` prefix.

Reference: https://api.docs.modulards.com/modular-ds-public-api/oauth/o-auth-discovery/retrieve-the-authorization-server-metadata

## Response

### 200

- `issuer` (string, optional) — Address of the authorization server.
- `authorization_endpoint` (string, optional) — Address where the user approves the client.
- `token_endpoint` (string, optional) — Address where the client exchanges a code or a refresh token for an access token.
- `registration_endpoint` (string, optional) — Address where a client registers itself.
- `response_types_supported` (list of enum, optional) — Response types the server supports; always `code`.
  - Allowed values: `code`
- `code_challenge_methods_supported` (list of enum, optional) — PKCE methods the server supports; always `S256`.
  - Allowed values: `S256`
- `scopes_supported` (list of string, optional) — Scopes a client can request: `mcp:use` and `offline_access`.
- `grant_types_supported` (list of enum, optional) — Grant types the server supports: `authorization_code` and `refresh_token`.
  - Allowed values: `authorization_code`, `refresh_token`

## Examples

**Response**

```json
{
  "issuer": "string",
  "authorization_endpoint": "string",
  "token_endpoint": "string",
  "registration_endpoint": "string",
  "response_types_supported": [
    "code"
  ],
  "code_challenge_methods_supported": [
    "S256"
  ],
  "scopes_supported": [
    "string"
  ],
  "grant_types_supported": [
    "authorization_code"
  ]
}
```

**SDK Code**

```python
import requests

url = "https://api.modulards.com/.well-known/oauth-authorization-server"

response = requests.get(url)

print(response.json())
```

```javascript
const url = 'https://api.modulards.com/.well-known/oauth-authorization-server';
const options = {method: 'GET'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.modulards.com/.well-known/oauth-authorization-server"

	req, _ := http.NewRequest("GET", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.modulards.com/.well-known/oauth-authorization-server")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.modulards.com/.well-known/oauth-authorization-server")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.modulards.com/.well-known/oauth-authorization-server');

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.modulards.com/.well-known/oauth-authorization-server");
var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/.well-known/oauth-authorization-server")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```