Implement OAuth Protected Resource Metadata
Publish OAuth Protected Resource Metadata so agents can discover how to authenticate per RFC 9728.
Requirements
- Serve JSON at
/.well-known/oauth-protected-resourcewith HTTP 200 - Include
resource(your resource identifier URL) - Include
authorization_servers(array of OAuth/OIDC issuer URLs) - Optionally include
scopes_supported - Optionally return
WWW-Authenticatewithresource_metadataon 401 responses
Cloudflare
Use Workers to serve the metadata endpoint and Access as the authorization server.
Validate
POST https://isitagentready.com/api/scan
Content-Type: application/json
{"url": "https://YOUR-SITE.com"}
Check that checks.discovery.oauthProtectedResource.status is "pass".