agentspeed.
Rubric / Discoverability

OAuth resource metadata

discoverability.oauth_protected_resource
weight 1deterministicemerging

`/.well-known/oauth-protected-resource` is published per RFC 9728 so agents can discover required scopes and authorization servers programmatically.

Adoption of what this check tests is still climbing, so failing it is an opportunity rather than a defect. Remediation lists rank these after established fixes, and the weight moves only when measurement earns it.

Definition
Check ID
discoverability.oauth_protected_resource
Category
Discoverability
Weight
1
Counts toward the score
Yes.
Evaluated by
A fixed rule with no threshold of our choosing. The same input always produces the same verdict.
Standard maturity
emerging
Canonical spec
https://datatracker.ietf.org/doc/html/rfc9728
Introduced in
r2026.04.2
Retired in
Still active.
History
Every change to the instrument— including the versions that changed this check
Machine-readable
/rubric.json— this check, and every other, as data
How often this check is right

No rate published. Too few labelled cases to publish a rate: 1 flagged case (30 needed to publish), 1 defective case (30 needed to publish). The counts are the honest answer here. The matrix behind discoverability.oauth_protected_resource is 3 labelled cases — reported here rather than turned into a percentage that would read as more certain than the evidence is.

Corpus v1, measured under rubric r2026.11.0. Full method and every other check at /rubric/accuracy.

How to fix it
Publish OAuth resource metadata at `/.well-known/oauth-protected-resource` per RFC 9728. Required for agents that act on behalf of authenticated users without hand-coded credentials.
Does your site pass this check?

Free scan, 30 seconds, no signup — this check and the other 35, with the exact evidence for each verdict.

Scan my site →
OAuth resource metadata · discoverability.oauth_protected_resource · AgentSpeed