`hermes mcp login <server> --flow device` took `authorization_servers[0]` from the protected-resource metadata and failed when that entry was a browser-only or issuer-inconsistent server, even though a later entry was the issuer-bound device_code server meant for headless clients (Higgsfield advertises exactly this shape: a PKCE server first, the device server second). Discovery now tries each advertised server in order and binds to the first whose metadata issuer matches its advertised URL and that offers device authorization. Issuer validation (RFC 8414 / SEP-2468) is unchanged per server; a single-server resource raises exactly the error it raised before, and a multi-server resource with no usable entry reports every attempt. The browser path (`tools/mcp_oauth_manager.py` pre-flight) is deliberately left on the SDK's own first-entry selection: the SDK's 401-branch discovery re-selects `authorization_servers[0]` itself, so a divergent pre-flight pick would only desynchronise the cached metadata from what the SDK authorizes against.
Website
This website is built using Docusaurus, a modern static website generator.
Installation
yarn
Local Development
yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
USE_SSH=true yarn deploy
Not using SSH:
GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.
Diagram Linting
CI runs ascii-guard to lint docs for ASCII box diagrams. Use Mermaid (````mermaid`) or plain lists/tables instead of ASCII boxes to avoid CI failures.