agentspeed.
Rubric / Discoverability

OAuth authorization metadata

discoverability.oauth_authorization_server
weight 1deterministicemerging

`/.well-known/oauth-authorization-server` is reachable and conforms to RFC 8414, letting agents discover authorization endpoints without out-of-band setup.

Adoption of what this check tests is still climbing, so failing it is an opportunity rather than a defect. Remediation lists rank these after established fixes, and the weight moves only when measurement earns it.

Definition
Check ID
discoverability.oauth_authorization_server
Category
Discoverability
Weight
1
Counts toward the score
Yes.
Evaluated by
A fixed rule with no threshold of our choosing. The same input always produces the same verdict.
Standard maturity
emerging
Canonical spec
https://datatracker.ietf.org/doc/html/rfc8414
Introduced in
r2026.04.2
Retired in
Still active.
History
Every change to the instrument— including the versions that changed this check
Machine-readable
/rubric.json— this check, and every other, as data
How often this check is right

No rate published. Too few labelled cases to publish a rate: 2 flagged cases (30 needed to publish), 2 defective cases (30 needed to publish). The counts are the honest answer here. The matrix behind discoverability.oauth_authorization_server is 5 labelled cases — reported here rather than turned into a percentage that would read as more certain than the evidence is.

Corpus v1, measured under rubric r2026.11.0. Full method and every other check at /rubric/accuracy.

How to fix it
Expose OAuth metadata at `/.well-known/oauth-authorization-server` per RFC 8414. Required for agents that need to perform user-authorized actions on your site.
Does your site pass this check?

Free scan, 30 seconds, no signup — this check and the other 35, with the exact evidence for each verdict.

Scan my site →
OAuth authorization metadata · discoverability.oauth_authorization_server · AgentSpeed