generated: '2026-08-29' method: probed source: https://mcp.groundcover.com/.well-known/oauth-protected-resource provider: Groundcover providerId: groundcover description: >- groundcover's only published OAuth surface is the remote MCP server. Its RFC 9728 Protected Resource Metadata declares exactly one scope. The REST API at api.groundcover.com does not use OAuth at all — it authenticates with a service-account bearer API key, and authorization is expressed through RBAC policies rather than scopes (see authentication/groundcover-authentication.yml). No scopes/permissions reference page exists in the docs; this file records what the server itself publishes. resource: https://mcp.groundcover.com/api/mcp authorization_servers: - https://mcp.groundcover.com bearer_methods_supported: - header scopes: - name: access:router description: >- The single scope advertised by groundcover's MCP protected-resource metadata. Grants an OAuth-authenticated agent access to the MCP router endpoint; groundcover publishes no per-tool or per-signal scope breakdown, so the effective permission is the one the logged-in member already holds under RBAC. source: https://mcp.groundcover.com/.well-known/oauth-protected-resource http_status: 200 probed: '2026-08-29' scope_count: 1 x-evidence: - url: https://mcp.groundcover.com/.well-known/oauth-protected-resource status: 200 - url: https://mcp.groundcover.com/.well-known/oauth-authorization-server status: 200