OAuth 2.1 protected MCP endpoint over Highlight staging data (read-only): meeting notes, open action items, live context, connected-service inventory, peer-tool discovery, MCP Apps UIs, and a per-grant audit trail.
Speaks MCP 2026-07-28 (stateless) with legacy initialize compatibility via the official TypeScript SDK / Cloudflare Agents handler.
Add it to a harness:
claude mcp add --transport http highlight https://mcp.prototypes.hlai.dev/mcp
Or in Cursor / any streamable-HTTP client, point at https://mcp.prototypes.hlai.dev/mcp — dynamic client
registration, PKCE, and the sign-in bounce are handled automatically.
Discovery: authorization server metadata · protected resource metadata · highlight-mcp manifest (v0.4.0 · 2026-07-29-deeplink-native-fallback)