MCP authorization
The MCP specification's OAuth-based framework for protecting servers reached over HTTP.
MCP authorization is the part of the Model Context Protocol specification that protects servers reached over HTTP. A protected MCP server acts as an OAuth resource server and the MCP client as an OAuth client acting for the resource owner, with tokens issued by an authorization server. Servers must validate that tokens were issued for them and must not accept or pass through other tokens, and clients should request only the scopes an operation needs. Local servers on standard input take credentials from the environment instead.
Agent Minute explains this term on 26 February 2027.
Related terms
MCP serverA service that exposes resources, prompts and tools to AI applications through the Model Context Protocol.Model Context Protocol (MCP)An open protocol for connecting AI applications to external tools and data through servers that expose them.OAuth 2.0The IETF framework that lets an application obtain limited access to a service on a user's behalf, without their password.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.OAuth scopeA value in an OAuth request naming the range of access a client asks for; the server may grant all, part or none of it.