Fix: protected-resource metadata lists public https authorization_servers

Web-audit fix skill for the mcp-auth-servers check (MCP, MAY).

Goal

List the authorization servers that issue tokens for your MCP server in its RFC 9728 metadata.

Fix

Publish authorization_servers in your protected-resource metadata as an array of at least one issuer URL. Each entry must be an absolute https URL on a public host, because a client fetches that authorization server's own metadata to begin the OAuth flow. A private, loopback, or http URL leaves every client outside your network unable to sign in.

Resources

Copy-paste prompt

Paste this into your coding agent. Your audit adds what it observed for this check:

Verify

Re-run the audit at https://anc.dev/audit or call the audit_website MCP tool; the mcp-auth-servers check should report pass.