Walk the OAuth discovery chain starting from an agent URL. Returns an
AuthorizationRequirements diagnostic record for a Bearer challenge (even
when later metadata is absent), or null when the probe is not a Bearer
401. Use hasValidatedMcpAuthorizationRequirements before promoting
the record to an interactive OAuth requirement.
Strategy:
POST tools/list to the agent with no Authorization header.
If 401 + WWW-Authenticate: Bearer: parse the challenge.
Resolve resource_metadata=…, or the RFC 9728 well-known fallback,
then GET it and read
resource + authorization_servers.
For the first authorization_servers[0]: GET /.well-known/oauth-authorization-server
and read authorization_endpoint, token_endpoint, registration_endpoint,
scopes_supported.
Return a structured record.
Anything missing from the chain surfaces as undefined on the result —
callers can still present a partial picture without re-probing.
Walk the OAuth discovery chain starting from an agent URL. Returns an
AuthorizationRequirementsdiagnostic record for a Bearer challenge (even when later metadata is absent), ornullwhen the probe is not a Bearer 401. Use hasValidatedMcpAuthorizationRequirements before promoting the record to an interactive OAuth requirement.Strategy:
tools/listto the agent with noAuthorizationheader.WWW-Authenticate: Bearer: parse the challenge.resource_metadata=…, or the RFC 9728 well-known fallback, then GET it and readresource+authorization_servers.authorization_servers[0]: GET/.well-known/oauth-authorization-serverand readauthorization_endpoint,token_endpoint,registration_endpoint,scopes_supported.Anything missing from the chain surfaces as
undefinedon the result — callers can still present a partial picture without re-probing.