generated: '2026-08-13' method: probed status: published source: https://console.gamesight.io/.well-known/oauth-protected-resource/mcp note: 'UPGRADE (2026-08-13). The 2026-07-19 pass concluded no Gamesight MCP server existed and wrote a derived candidate tool list with `deployment.mode: none`. That was wrong. Gamesight runs a real, hosted, remote MCP server at https://console.gamesight.io/mcp. It was found by probing the API hosts named in the provider''s own OpenAPI servers[]: api.marketing.gamesight.io serves an RFC 8414 OAuth Authorization Server Metadata document whose only supported scope is "mcp". POSTing a JSON-RPC tools/list to https://console.gamesight.io/mcp returns HTTP 401 {"error":"invalid_token"} with a WWW-Authenticate header whose resource_metadata parameter points at https://console.gamesight.io/.well-known/oauth-protected-resource/mcp — an RFC 9728 document that names the resource "Gamesight MCP Server". Gamesight does not document this server anywhere in its public docs: it is absent from docs.gamesight.io/llms.txt, and /docs/mcp, /docs/mcp-server and /docs/ai-agents all 404. The endpoint is real and provider-served; the tool surface is OAuth-gated and therefore not enumerable anonymously.' deployment: mode: none verified: derived tools: 14 checked: '2026-08-12' source: catalog MCP census server: name: Gamesight MCP Server transport: http url: https://console.gamesight.io/mcp resource_metadata: https://console.gamesight.io/.well-known/oauth-protected-resource/mcp documented_publicly: false authorization: issuer: https://console.gamesight.io authorization_endpoint: https://console.gamesight.io/authorize token_endpoint: https://console.gamesight.io/api/app/oauth/token registration_endpoint: https://console.gamesight.io/api/app/oauth/register revocation_endpoint: https://console.gamesight.io/api/app/oauth/revoke grant_types: - authorization_code - refresh_token response_types: - code code_challenge_methods: - S256 token_endpoint_auth_methods: - client_secret_post - client_secret_basic scopes_supported: - mcp bearer_methods_supported: - header dynamic_client_registration: true metadata_documents: - well-known/gamesight-oauth-authorization-server.json - well-known/gamesight-console-oauth-authorization-server.json - well-known/gamesight-oauth-protected-resource-mcp.json tools: status: gated count: null note: tools/list requires an OAuth bearer token with the "mcp" scope. No tool list is published in the docs or llms.txt, so the real tool names and inputSchemas cannot be established without an authenticated introspection. NOTHING IS INVENTED HERE. The derived one-tool-per-operation candidate list written in round 1 has been moved to mcp/gamesight-tool-crosswalk.yml as REST-side surface only; it is explicitly NOT a claim about what this server exposes. x-evidence: - fetched: '2026-08-13' url: https://console.gamesight.io/mcp method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' http_status: 401 response: '{"error": "invalid_token", "error_description": "Authentication required"}' www_authenticate: Bearer error="invalid_token", error_description="Authentication required", resource_metadata="https://console.gamesight.io/.well-known/oauth-protected-resource/mcp" - fetched: '2026-08-13' url: https://console.gamesight.io/.well-known/oauth-protected-resource/mcp http_status: 200 content_type: application/json resource_name: Gamesight MCP Server - fetched: '2026-08-13' url: https://api.marketing.gamesight.io/.well-known/oauth-authorization-server http_status: 200 content_type: application/json