Trust and Authorization in MCP
OAuth 2.1, the resource-server model, RFC 8707, and the threats the protocol cannot solve for you.
The security axis of MCP: how authorization works on the HTTP transport with OAuth 2.1, the server-as-resource-server model and RFC 8707 resource indicators, the later OIDC discovery and incremental-consent refinements, and the three threat classes, token passthrough, confused deputy, and prompt injection via tool output, with the guard for each.
- MCP
