An MCP server's URL is not only where you connect. It is the OAuth resource identifier the client binds its token to.
That makes it a value that must be exactly what the client connects to — not merely equivalent, not a redirect target, not the same host with a different path.
⚠️ A wrong value here passes every local check and fails only inside a real client's handshake. Nothing in your own test suite can tell you: the challenge your server returns on an unauthenticated request, and the discovery document that describes it, are produced by two separate code paths.
So check them against each other, never individually. Fetch the 401 challenge, fetch the discovery document, and compare the identifier in one against the resource in the other. Both being individually plausible is exactly the failure state.
The same reasoning is why the endpoint has no path. A bare host root cannot disagree with itself about where the resource begins.