Retrieve the protected resource metadata
Returns the OAuth protected resource metadata (RFC 9728): the resource an MCP client is about to use, the authorization server that guards it and the scope it asks for (mcp:use). A client that only knows the MCP address reads it to find where to authorize, then continues with “Retrieve the authorization server metadata”.
Public, served at the root of the MCP host, without the /api prefix.
Response
resource
Address of the protected resource, the MCP host.
scopes_supported
Scope the resource asks for: mcp:use.
