OAuth resource metadata
`/.well-known/oauth-protected-resource` is published per RFC 9728 so agents can discover required scopes and authorization servers programmatically.
Adoption of what this check tests is still climbing, so failing it is an opportunity rather than a defect. Remediation lists rank these after established fixes, and the weight moves only when measurement earns it.
No rate published. Too few labelled cases to publish a rate: 1 flagged case (30 needed to publish), 1 defective case (30 needed to publish). The counts are the honest answer here. The matrix behind discoverability.oauth_protected_resource is 3 labelled cases — reported here rather than turned into a percentage that would read as more certain than the evidence is.
Corpus v1, measured under rubric r2026.11.0. Full method and every other check at /rubric/accuracy.
Publish OAuth resource metadata at `/.well-known/oauth-protected-resource` per RFC 9728. Required for agents that act on behalf of authenticated users without hand-coded credentials.
Free scan, 30 seconds, no signup — this check and the other 35, with the exact evidence for each verdict.
Scan my site →