Fix: protected-resource metadata lists public https authorization_servers
Web-audit fix skill for the
mcp-auth-serverscheck (MCP, MAY).
Goal
List the authorization servers that issue tokens for your MCP server in its RFC 9728 metadata.
Fix
Publish authorization_servers in your protected-resource metadata as an array of at least one issuer URL. Each entry must be an absolute https URL on a public host, because a client fetches that authorization server's own metadata to begin the OAuth flow. A private, loopback, or http URL leaves every client outside your network unable to sign in.
Resources
Copy-paste prompt
Paste this into your coding agent. Your audit adds what it observed for this check:
Verify
Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-servers check should report pass.