MCP Toolkit MCP 2026-07-28

MCP Protected Resource Metadata Validator

Check the metadata document that tells an MCP client which protected resource it is accessing and which authorization servers can authorize it.

Input

Static validation only Ready.

Result

Run the tool to see the analysis.

Check protected-resource discovery metadata

Protected Resource Metadata connects an MCP resource server with the authorization server or servers that can issue credentials for it. Incorrect metadata can cause authorization discovery and issuer-selection failures.

What this tool helps you check

Validate OAuth Protected Resource Metadata for an MCP server including resource identifier and authorization servers.

Use MCP Protected Resource Metadata Validator as a focused pre-flight utility while building, reviewing or debugging an MCP integration. Paste the relevant configuration, protocol message, metadata, schema or value into the tool and review the returned findings before the same data reaches a production client or server.

How to interpret the result

Authorization metadata must be treated as security-sensitive configuration. Static validation can reveal obvious inconsistencies, but a production OAuth deployment must also validate live issuer, redirect, token and authorization behavior at runtime.

A clean result means the input passed the rules implemented by this utility. It does not guarantee application security, protocol interoperability or correct business behavior. Test important integrations against the exact MCP client, SDK, gateway and server versions used in your deployment.