MCP / OAuth integration

Production MCP endpoint: /mcp.

Protected Resource Metadata: /.well-known/oauth-protected-resource.

Authorization Server Metadata: /.well-known/oauth-authorization-server.

Required scope: cockpit.read. Authorization Code + PKCE S256 and Dynamic Client Registration are supported. Access is read-only.