cos-mcp (OAuth 2.1 protected — Chief of Staff task board) Endpoints: POST /mcp — MCP Streamable HTTP (requires OAuth bearer) GET /authorize?admin=... — Consent screen (admin-gated) POST /authorize?admin=... — Approve client (admin-gated) GET /.well-known/oauth-authorization-server — RFC 8414 metadata (library) GET /.well-known/oauth-protected-resource — RFC 9728 metadata (library) POST /oauth/token — Token endpoint (library) POST /oauth/register — Dynamic Client Registration (library, rate-limited) GET /healthz — Liveness (no auth; handled before this host gate) The board/API at cos.tuckerza.com is NOT reachable from this hostname.