Whether a discovery record proves the MCP endpoint is OAuth protected.
discoverAuthorizationRequirements intentionally returns partial records
for diagnostics. Those records are not sufficient evidence for an
interactive OAuth prompt: the MCP authorization profile requires protected
resource metadata whose resource exactly identifies the endpoint and
which names at least one authorization server.
Whether a discovery record proves the MCP endpoint is OAuth protected.
discoverAuthorizationRequirementsintentionally returns partial records for diagnostics. Those records are not sufficient evidence for an interactive OAuth prompt: the MCP authorization profile requires protected resource metadata whoseresourceexactly identifies the endpoint and which names at least one authorization server.