MCP & Configuration
MCP OAuth Discovery Checker
Inspect public protected-resource and authorization-server metadata without signing in.
Processed on our CPU server.Submitted input is processed for this run and is not stored. This server contacts the public MCP/discovered metadata URLs. No credentials are sent; query values are redacted in reports.
256 KiB limitInput
Result
A useful result starts here.
Paste your input or load an example,
then run the tool.
Supported formats & limitations
- MCP 2025-11-25 / RFC 9728 / RFC 8414 authorization-code discovery subset. Challenge or path-aware protected-resource metadata, up to two OAuth server documents, 64 KiB each, eight seconds total.
- Compare exact resource/issuer, bounded HTTPS endpoints and S256 advertisement. Endpoint destinations are validated but not invoked. No OIDC fallback, login, registration, credential or token exchange.
Execution budget: 10s; output limit: 4096 KiB. Browser worker startup has a separate 3s allowance.