An unauthenticated request returns
401 with a WWW-Authenticate header that names the resource metadata URL and the scopes to request. Clients that follow the MCP authorization specification discover everything from there and open the browser for sign-in. Tokens go in the Authorization: Bearer header.
Clients that cannot run an OAuth flow are not supported yet.
See what you are granting for what each scope allows and Tools for the catalog.