Go deeper

Sources & further reading

The primary sources behind the talk, the MCP authorization timeline, and where to explore next.

Reference · MCP Authorization

How MCP auth hardened, version by version

  1. 2024-11-05

    Initial spec

    No standard authorization; trust assumed in local use.

  2. 2025-03-26

    Auth framework

    OAuth 2.1 foundations introduced for remote servers.

  3. 2025-06-18

    OAuth Resource Server

    Resource indicators (RFC 8707) bind a token to one audience.

  4. 2025-11-25

    Enterprise-ready

    CIMD replaces dynamic registration; enterprise IdP policy; async Tasks.

The trajectory: From implicit local trust to audience-bound tokens and enterprise identity policy in twelve months.