> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://api.docs.modulards.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://api.docs.modulards.com/_mcp/server.

# Retrieve the protected resource metadata

GET https://api.modulards.com/.well-known/oauth-protected-resource

Returns the OAuth protected resource metadata (RFC 9728): the resource an MCP client is about to use, the authorization server that guards it and the scope it asks for (`mcp:use`). A client that only knows the MCP address reads it to find where to authorize, then continues with "Retrieve the authorization server metadata".

Public, served at the root of the MCP host, without the `/api` prefix.

Reference: https://api.docs.modulards.com/modular-ds-public-api/oauth/o-auth-discovery/retrieve-the-protected-resource-metadata

## Response

### 200

- `resource` (string, optional) — Address of the protected resource, the MCP host.
- `authorization_servers` (list of string, optional) — Authorization servers that guard the resource.
- `scopes_supported` (list of string, optional) — Scope the resource asks for: `mcp:use`.

## Examples

**Response**

```json
{
  "resource": "string",
  "authorization_servers": [
    "string"
  ],
  "scopes_supported": [
    "string"
  ]
}
```

**SDK Code**

```python
import requests

url = "https://api.modulards.com/.well-known/oauth-protected-resource"

response = requests.get(url)

print(response.json())
```

```javascript
const url = 'https://api.modulards.com/.well-known/oauth-protected-resource';
const options = {method: 'GET'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.modulards.com/.well-known/oauth-protected-resource"

	req, _ := http.NewRequest("GET", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.modulards.com/.well-known/oauth-protected-resource")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.modulards.com/.well-known/oauth-protected-resource")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.modulards.com/.well-known/oauth-protected-resource');

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.modulards.com/.well-known/oauth-protected-resource");
var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://api.modulards.com/.well-known/oauth-protected-resource")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```