# OAuth 2.1 + MCP Authorization

> The current MCP specification (version 2026-07-28) treats MCP servers as OAuth 2.1 resource servers, requiring PKCE (S256) and the RFC 8707 resource parameter, and the 2026 revision added RFC 9207 issuer validation and a shift toward Client ID Metadata Documents; note that OAuth 2.1 is still an IETF Internet-Draft, while RFC 9728 (OAuth 2.0 Protected Resource Metadata, using /.well-known/oauth-protected-resource) is a published Standards Track RFC.

The open authorization stack MCP servers are expected to implement.

- **Category:** Identity & Permission
- **License:** Open standard (IETF / MCP specification)
- **Language:** N/A (specification)
- **Self-hosted:** No
- **Last verified:** 2026-10-04

> Caveat: OAuth 2.1 has not yet become an RFC; it remains an Internet-Draft referenced by the MCP specification.

Source: https://agent.c8.fit/tools/oauth21-mcp-authorization/
