# Fix: protected-resource metadata lists public https authorization_servers

> Web-audit fix skill for the `mcp-auth-servers` check (MCP, MAY).

## Goal

List the authorization servers that issue tokens for your MCP server in its RFC 9728 metadata.

## Fix

Publish `authorization_servers` in your protected-resource metadata as an array of at least one
issuer URL. Each entry must be an absolute `https` URL on a public host, because a client fetches
that authorization server's own metadata to begin the OAuth flow. A private, loopback, or `http`
URL leaves every client outside your network unable to sign in.

## Resources

- [RFC 9728 section 2](https://www.rfc-editor.org/rfc/rfc9728#section-2)
- [MCP authorization](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)

## Copy-paste prompt

Paste this into your coding agent. [Your audit](https://anc.dev/audit) adds what it observed for this check:

```text
Goal: List the authorization servers that issue tokens for your MCP server in its RFC 9728 metadata
Fix: Publish `authorization_servers` in your protected-resource metadata as an array of at least one issuer URL. Each entry must be an absolute `https` URL on a public host, because a client fetches that authorization server's own metadata to begin the OAuth flow. A private, loopback, or `http` URL leaves every client outside your network unable to sign in.
Skill: https://anc.dev/fix/mcp-auth-servers
Docs: https://www.rfc-editor.org/rfc/rfc9728#section-2, https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization
```

## Verify

Re-run the audit at [https://anc.dev/audit](https://anc.dev/audit) or call the `audit_website` MCP tool; the `mcp-auth-servers` check should report `pass`.
