OAuth Authorization Server Metadata and Protected Resource Metadata are public, unauthenticated, and generally not tenant-specific. They are useful for endpoint discovery and broad capability negotiation, but a Resource Authorization Server may not want to publish its complete resources, scopes, Rich Authorization Request (RAR) types, claim requirements, or tenant-specific eligibility anonymously.
This creates a scalability problem for cross-domain grants such as the Identity Assertion JWT Authorization Grant (ID-JAG). IdP administrators need to know what a Resource Authorization Server accepts before they can author policy, but today they typically learn that from documentation and reproduce it manually.
The MVP separates three questions: