Walks through a structured production readiness checklist for Scalekit MCP authentication implementations. Use when the user says they are going live, launching to production, doing a pre-launch review, or wants to verify their MCP server authentication is production-ready.
Work through each section in order — earlier sections are blockers for later ones.
state parameter in callbacks (CSRF protection)httpOnly, secure, and sameSite flags/.well-known/oauth-protected-resourceKey metrics: