This path lets a reverse proxy or serverless platform authenticate a bearer
token first while the MCP runtime still enforces this deployment's issuer,
audience/resource, token type, algorithm, scopes, subject allowlist, and
lifetime rules.
Throws
OAuthError when the auth info does not satisfy this deployment.
Validate auth info supplied by trusted middleware before MCP handling.