Validates OAuth 2.0 Protected Resource Metadata per RFC 9728: resource URI, authorization servers, supported scopes, and bearer methods. Middle node of the mcp-server-governance-conformance chain.
Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.
Run the AINumbers MCP tool `validate_mcp_authorization_metadata`. Task: Validate OAuth 2.0 Protected Resource Metadata per RFC 9728 for MCP server authorization: resource URI, authorization servers, supported scopes, and bearer methods.
Call it with arguments: {"policy_parameters":{"metadata":{"resource":"https://api.example.com/mcp","authorization_servers":["https://auth.example.com"],"scopes_supported":["tools:read","tools:call"],"bearer_methods_supported":["header"]}}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-148-mcp-authorization-metadata-validator.html#p=v1.H4sIAAAAAAAA_wHBAD7_eyJtZXRhZGF0YSI6eyJyZXNvdXJjZSI6Imh0dHBzOi8vYXBpLmV4YW1wbGUuY29tL21jcCIsImF1dGhvcml6YXRpb25fc2VydmVycyI6WyJodHRwczovL2F1dGguZXhhbXBsZS5jb20iXSwic2NvcGVzX3N1cHBvcnRlZCI6WyJ0b29sczpyZWFkIiwidG9vbHM6Y2FsbCJdLCJiZWFyZXJfbWV0aG9kc19zdXBwb3J0ZWQiOlsiaGVhZGVyIl19fVfAOwHBAAAA