Skip to content
A

OAuth 2.1 + MCP Authorization

Identity & PermissionStandard / spec · Open standard (IETF / MCP specification)Managed only

The open authorization stack MCP servers are expected to implement.

The current MCP specification (version 2026-07-28) treats MCP servers as OAuth 2.1 resource servers, requiring PKCE (S256) and the RFC 8707 resource parameter, and the 2026 revision added RFC 9207 issuer validation and a shift toward Client ID Metadata Documents; note that OAuth 2.1 is still an IETF Internet-Draft, while RFC 9728 (OAuth 2.0 Protected Resource Metadata, using /.well-known/oauth-protected-resource) is a published Standards Track RFC.

Caveat: OAuth 2.1 has not yet become an RFC; it remains an Internet-Draft referenced by the MCP specification.

Key facts

CategoryIdentity & Permission
LicenseOpen standard (IETF / MCP specification)
LanguageN/A (specification)
Self-hostedNo
Last verified2026-10-04

Markdown version (for LLMs)

Tools in this category