generated: '2026-09-04' method: probed source: https://skills.workera.ai/.well-known/oauth-protected-resource/mcp name: Workera MCP Server status: published vendor_official: true deployment: mode: remote endpoint: https://skills.workera.ai/mcp auth: oauth verified: probed probe_prior: (never probed) probe: gated probe_why: RFC 9728 challenge on the MCP path only checked: '2026-09-11' source: claimed-backlog re-probe 2026-09-11 discovery: protected_resource: https://skills.workera.ai/.well-known/oauth-protected-resource/mcp authorization_server: https://skills.workera.ai/.well-known/oauth-authorization-server files: - well-known/workera-oauth-protected-resource-mcp.json - well-known/workera-oauth-authorization-server.json authorization: model: oauth2 issuer: https://skills.workera.ai authorization_endpoint: https://skills.workera.ai/mcp/oauth/authorize token_endpoint: https://skills.workera.ai/mcp/oauth/token registration_endpoint: https://skills.workera.ai/mcp/oauth/register dynamic_client_registration: true client_id_metadata_document_supported: false grant_types_supported: - authorization_code - refresh_token code_challenge_methods_supported: - S256 response_types_supported: - code response_modes_supported: - query token_endpoint_auth_methods_supported: - none - client_secret_basic - client_secret_post scopes_supported: - mcp bearer_methods_supported: - header tools: known: false count: null note: 'tools/list is auth-gated. An anonymous POST of {"jsonrpc":"2.0","id":1,"method":"tools/list"} to https://skills.workera.ai/mcp returns HTTP 401 with body {"error":"unauthorized"} and a WWW-Authenticate: Bearer resource_metadata="https://skills.workera.ai/.well-known/oauth-protected-resource/mcp", scope="mcp" challenge. `initialize` returns the same 401. Workera publishes no tool list in an llms.txt, a docs page or a repository, so the tool names and inputSchemas are NOT recorded here. Establishing them requires an authenticated OAuth introspection with a Workera account. No tool has been guessed or derived — see mcp/workera-tool-crosswalk.yml.' supported_clients: evidence: 'The application''s Content-Security-Policy form-action directive on skills.workera.ai enumerates the OAuth redirect targets Workera has allow-listed, which is a first-party statement of the MCP clients it expects: https://claude.ai, https://chatgpt.com, the chatgpt: scheme, http://127.0.0.1:* (local MCP clients), https://teams.microsoft.com and https://*.glean.com.' clients: - Claude - ChatGPT - local MCP clients on 127.0.0.1 - Microsoft Teams - Glean probes: - url: https://skills.workera.ai/.well-known/oauth-protected-resource/mcp method: GET status: 200 content_type: application/json - url: https://skills.workera.ai/.well-known/oauth-authorization-server method: GET status: 200 content_type: application/json - url: https://skills.workera.ai/mcp method: POST body: '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' status: 401 response: '{"error":"unauthorized"}' - url: https://skills.workera.ai/mcp method: POST body: '{"jsonrpc":"2.0","id":1,"method":"initialize"}' status: 401 response: '{"error":"unauthorized"}'