OAuth protected resource metadata

RFC 9728 Protected Resource Metadata for a surface-specific MCP endpoint. Public (no auth).

Authentication

AuthorizationBearer
API key or Clerk session token

Path parameters

productIdstringRequired
surfaceIdstringRequired

Response

RFC 9728 protected resource metadata
authorization_serverslist of strings
bearer_methods_supportedlist of strings
resourcestring

Errors

500
Internal Server Error