Skip to content

Trailing slash in .well-known/oauth-protected-resource response may violate “Canonical Server URI” requirement #1265

Description

@FakeDocument

Question

As I understand it, https://your-mcp.com/.well-known/oauth-protected-resource should return:

{
    "resource": "https://your-mcp.com",
    "authorization_servers": [
        "https://your-auth.com"
    ],
    "scopes_supported": [],
    "bearer_methods_supported": [
        "header"
    ]
}

However, it actually returns:

{
    "resource": "https://your-mcp.com/",
    "authorization_servers": [
        "https://your-auth.com/"
    ],
    "scopes_supported": [],
    "bearer_methods_supported": [
        "header"
    ]
}

Note the trailing / in both the resource and authorization_servers values.

According to the MCP spec’s “resource-parameter-implementation” section, I believe this violates the requirement for canonicalization:
https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization#resource-parameter-implementation

Is this a bug, or am I misunderstanding the requirement?

Activity

  1. added
    authIssues and PRs related to Authentication / OAuth
    ready for workEnough information for someone to start working on
    P3Nice to haves, rare edge cases
    on Oct 3, 2025
  2. added
    bugSomething isn't working
    P1Significant bug affecting many users, highly requested feature
    and removed
    questionFurther information is requested
    P3Nice to haves, rare edge cases
    on Jan 22, 2026
  3. added a commit that references this issue on Jan 23, 2026
    96c7a43
  4. lawrence3699 commented on Apr 17, 2026

    @lawrence3699

    I reproduced this on : the protected resource metadata endpoint serializes host-only and values with an implicit trailing (for example ). I have a focused fix and regression test prepared against that keeps route registration unchanged and only canonicalizes those root server URIs in the JSON response.

  5. lawrence3699 commented on Apr 17, 2026

    @lawrence3699

    I reproduced this on v1.x: the protected resource metadata endpoint serializes host-only resource and authorization_servers values with an implicit trailing / (for example https://example.com/).

    I have a focused fix and regression test prepared against v1.x that keeps route registration unchanged and only canonicalizes those root server URIs in the JSON response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1Significant bug affecting many users, highly requested featureauthIssues and PRs related to Authentication / OAuthbugSomething isn't workingready for workEnough information for someone to start working on

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions