RFC 9728, OAuth 2.0 protected resource metadata
Published in April 2025, this defines a metadata document a protected resource publishes so a client can discover how to talk to it, including which authorization servers it trusts. It is the discovery leg of agent authorization: an agent meeting an unfamiliar server learns where to get a token instead of guessing.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0009
- Kind
- Standard or protocol
- Jurisdiction
- Global
- Last verified
- Added
- The specification defines a metadata format an OAuth client or authorization server can use to obtain the information needed to interact with a protected resource.
- MCP servers must implement it, and MCP clients must use it for authorization server discovery.
- The metadata is reached from a WWW-Authenticate header on a 401 response, so discovery starts from a refusal.
- Section 7.7 of the document is the basis for blocking private and reserved address ranges when fetching discovery URLs.
Dimension by dimension
2 dimensions, each one stated, silent or open
Authorization, Identity. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- AuthorizationStated
- It tells a client which authorization servers a resource accepts tokens from, which is the first decision in any agent to tool handshake.RFC Editor, RFC 9728, primary source, 1 April 2025.
- IdentityStated
- The resource names itself in its own metadata, giving the client a canonical identifier to bind a token to.RFC Editor, RFC 9728, primary source, 1 April 2025.
What it changes
For a team deploying an agent
This is what lets an agent connect to a tool nobody pre configured. It is also a server side request forgery surface, because the agent is fetching URLs a remote server chose. Require HTTPS, block private ranges, and validate redirect targets before your client follows anything it discovered.
Sources
What this record was verified against
- RFC Editor, RFC 9728Primary · 1 April 2025
Related
Records that sit beside this one
Model Context Protocol authorization
Global · verified 15 September 2026
Authorization servers must implement OAuth 2.1 with appropriate security measures for both confidential and public clients.
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0009 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), rfc 9728, oauth 2.0 protected resource metadata.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). RFC 9728, OAuth 2.0 protected resource metadata. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0009-rfc-9728-oauth-2-0-protected-resource-metadata
- MLA
- "RFC 9728, OAuth 2.0 protected resource metadata." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0009-rfc-9728-oauth-2-0-protected-resource-metadata.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "RFC 9728, OAuth 2.0 protected resource metadata." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0009-rfc-9728-oauth-2-0-protected-resource-metadata.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0009-rfc-9728-oauth-2-0-protected-resource-metadata
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every standard or protocol record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.