MCP authentication by identity provider

Identity providers do not agree on the OAuth primitives the MCP specification builds on, and they move. Each page below documents how one provider deviates, how a credential-less scan fingerprints it, and the production failure the deviation predicts.

Check any MCP server against these in one command: npx mcpcomp <server-url>