System

​

Infrastructure, discovery, and protocol endpoints that live at the host root, outside the /v1 prefix. All of them except the MCP endpoint work without authentication.

  • GET /ping — liveness/health check. Returns { "ok": true }.
  • POST / — the MCP server: JSON-RPC over the Model Context Protocol's Streamable HTTP transport. Authenticate it like the REST API.
  • GET /.well-known/oauth-protected-resource — OAuth 2.0 Protected Resource Metadata (RFC 9728). Names the protected resource and the authorization server that issues tokens for it.
  • GET /.well-known/oauth-authorization-server — OAuth 2.0 Authorization Server Metadata (RFC 8414), describing the authorization-code + PKCE flow. Also served at /.well-known/openid-configuration.

Because these paths are not under /v1, each operation declares its own host-root server.

Note that the two metadata documents are served by different hosts. The Protected Resource Metadata comes from the platform host and points at the authorization server; the Authorization Server Metadata itself is served by the Paperpile API host (https://stage-api.paperpile.com). Discover the OAuth endpoints from that document rather than hard-coding them — see Authentication.