Chronicle/Policy & standards

MCP specification revision classifies servers as OAuth resource servers and adds security best practices

PolicyStandardSignificance assistant-drafted

The 2025-06-18 revision of the Model Context Protocol specification classifies MCP servers as OAuth resource servers with protected resource metadata, and requires clients to implement RFC 8707 resource indicators so malicious servers cannot obtain tokens meant for others. It also clarifies authorization security considerations and adds a security best practices page.

Why it matters

It is the main protocol-level change addressing token misuse between MCP clients and servers.

Key facts

As stated in the sources, with where to find them.

  • Changes include classifying MCP servers as OAuth Resource Servers (PR #338) and requiring RFC 8707 Resource Indicators in clients (PR #734).Major changes, items 3-4
  • Adds clarified authorization security considerations and a new security best practices page.Major changes, item 5

Findings that cite this record

No tracked finding cites this record yet.

Key questions this bears on

Sources

Related records