MCP / OAuth integration
Production MCP endpoint: /mcp.
Protected Resource Metadata: /.well-known/oauth-protected-resource.
Authorization Server Metadata: /.well-known/oauth-authorization-server.
Required scope: cockpit.read. Authorization Code + PKCE S256 and Dynamic Client Registration are supported. Access is read-only.