APP_ORIGIN/mcp. The endpoint is OAuth-protected and advertises protected-resource metadata. Compatible clients discover authorization, use PKCE S256, and request only the scopes they need. The server is stateless; each request is tenant-isolated.
code: message. Credentials and signing secrets are never accepted or returned.