Skip to content
varsafe
Esc
↑↓navigate↵open⌘Jpreview

OAuth 2.1 authorization server metadata

RFC 8414 metadata describing the authorization and token endpoints, supported grant types and the scope vocabulary used by the MCP endpoint.

GET/.well-known/oauth-authorization-server
Responses
200RFC 8414 authorization server metadata.
issuerstring<uri>required
authorization_endpointstring<uri>required
token_endpointstring<uri>required
registration_endpointstring<uri>
Dynamic client registration (RFC 7591), when enabled.
scopes_supportedstring[]
response_types_supportedstring[]required
grant_types_supportedstring[]
code_challenge_methods_supportedstring[]
400The request failed validation. `field` names the offending input.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
404The resource does not exist, or is not visible to this credential.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
429Rate limited. Retry after the interval named in the response.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
500Unexpected server error. The body never carries internal detail.
statusCodeintegerrequired
HTTP status code, repeated in the body.
min -9007199254740991 · max 9007199254740991
codestringrequired
Stable machine-readable error code, e.g. `SECRET_NOT_FOUND` or `FORBIDDEN`. Branch on this, never on the message.
messagestringrequired
Human-readable explanation. Wording may change.
fieldstring
The offending request field, present on validation failures.
Request
curl -X GET "https://api.varsafe.dev/.well-known/oauth-authorization-server"
Response
{
  "issuer": "<uri>",
  "authorization_endpoint": "<uri>",
  "token_endpoint": "<uri>",
  "registration_endpoint": "<uri>",
  "scopes_supported": [
    "string"
  ],
  "response_types_supported": [
    "string"
  ],
  "grant_types_supported": [
    "string"
  ],
  "code_challenge_methods_supported": [
    "string"
  ]
}