---
term: "MCP authorization"
category: "Agent protocols"
url: https://agenticopenfinance.com/glossary/mcp-authorization
source: AgenticOpenFinance glossary
---

# MCP authorization

> The MCP specification's OAuth-based framework for protecting servers reached over HTTP.

MCP authorization is the part of the Model Context Protocol specification that protects servers reached over HTTP. A protected MCP server acts as an OAuth resource server and the MCP client as an OAuth client acting for the resource owner, with tokens issued by an authorization server. Servers must validate that tokens were issued for them and must not accept or pass through other tokens, and clients should request only the scopes an operation needs. Local servers on standard input take credentials from the environment instead.

Related terms: [MCP server](https://agenticopenfinance.com/glossary/mcp-server.md), [Model Context Protocol (MCP)](https://agenticopenfinance.com/glossary/model-context-protocol.md), [OAuth 2.0](https://agenticopenfinance.com/glossary/oauth-2.md), [Access token](https://agenticopenfinance.com/glossary/access-token.md), [OAuth scope](https://agenticopenfinance.com/glossary/oauth-scope.md)
