oauth.mcp.acme-corp.ai - the OAuth-protected copy of the MCP endpoints. Get a token from /realms/mcp/protocol/openid-connect/token with grant_type=client_credentials, then POST /mcp or //mcp with Authorization: Bearer . Discovery: /realms/mcp/.well-known/openid-configuration. The same tools with no auth at all: https://mcp.acme-corp.ai/mcp