The 2025-06-18 revision of the Model Context Protocol specification classifies MCP servers as OAuth resource servers with protected resource metadata, and requires clients to implement RFC 8707 resource indicators so malicious servers cannot obtain tokens meant for others. It also clarifies authorization security considerations and adds a security best practices page.
Why it matters
It is the main protocol-level change addressing token misuse between MCP clients and servers.
Key facts
As stated in the sources, with where to find them.
- Changes include classifying MCP servers as OAuth Resource Servers (PR #338) and requiring RFC 8707 Resource Indicators in clients (PR #734).Major changes, items 3-4
- Adds clarified authorization security considerations and a new security best practices page.Major changes, item 5
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
May 20, 2026
Sep 30, 2025
Apr 1, 2025
Mar 30, 2025
Apr 15, 2026
Sep 11, 2026