MCP 101 (mcp vs api, mcp servers, spec updates, mcp oauth)
MCP OAuth and Authentication Flows
MCP servers moved from issuing tokens themselves to accepting them from external identity providers.
Jonah Kaur
Staff Writer · · 12 min read
MCP servers moved from issuing tokens themselves to accepting them from external identity providers.
Connecting untrusted MCP servers puts agents inside your reasoning loop with minimal oversight.
The spec now enforces OAuth security, structured tool outputs, and user-gating within sessions.
Autonomous agents amplify API vulnerabilities because they operate unsupervised across sessions.
The MCP ecosystem exploded from 100 servers to over 21,000 in eighteen months.
OWASP's LLM Top 10 risks take on new forms in MCP, from tool poisoning to credential leaks.
LLM architecture conflates instructions and data, making both attacks systematically hard to stop.
Production agents require memory, tools, and coordination layers beyond the model itself.