Skip to content
#

rfc9728

Here are 9 public repositories matching this topic...

Diagnose OAuth discovery problems on remote MCP servers: the 401 challenge, RFC 9728 protected resource metadata, authorization server metadata, PKCE S256, client registration, token endpoint error format and an optional PKCE login, checked against the MCP 2026-07-28 and 2025-11-25 authorization rules. Read-only CLI, httpx only, pipx or uvx.

  • Updated Oct 5, 2026
  • Python

OAuth 2.0 bearer-token resource server for Rust HTTP services: JWT access-token validation against a JWKS, RFC 9728 protected-resource metadata, RFC 6750 WWW-Authenticate challenges, an optional static API key, and axum integration. Provider-agnostic (Authentik, Authelia, Kanidm) — every difference is config, never a code branch.

  • Updated Oct 5, 2026
  • Rust

Add this topic to your repo

To associate your repository with the rfc9728 topic, visit your repo's landing page and select "manage topics."

Learn more