AI Strategy

Securing MCP in Production: OAuth, Agent Identity, and What a 2026 Security Review Actually Covers

September 3, 2026 · 9 min read | AI Strategy

The protocol’s auth story has matured fast. The gaps that actually hurt companies in production are mostly somewhere else — here is where we look.

When we explained MCP for business readers, we flagged two risks vendors gloss over: prompt injection and over-permissioning. Both still matter. But a year of production deployments — and two major specification releases — have made the security picture much more specific. This post is the deeper cut: what the protocol now handles for you, what it deliberately leaves to you, and the review we run before an MCP integration touches real customer data.

The good news first: MCP auth grew up

Early MCP deployments handled authorization with whatever the integrator improvised. That era is over. Three changes, rolled out across the 2025–2026 spec releases, closed the most dangerous protocol-level gaps:

1
Tokens are bound to one server
MCP servers are formal OAuth resource servers, and resource indicators (RFC 8707) are mandatory — a token issued for your CRM connector cannot be replayed against your billing connector. Token-passthrough designs, where one stolen credential opened everything, are off the table.
2
Issuer validation stops mix-up attacks
The July 2026 spec release added RFC 9207 issuer validation, so a malicious or misconfigured authorization server can no longer trick a client into sending credentials to the wrong place. Client credentials are also now bound to the authorization server that issued them.
3
CIMD replaced dynamic registration
Dynamic Client Registration — every AI client self-registering into your auth server’s database — is deprecated in favour of Client ID Metadata Documents: the client’s identity is a document at a URL you can verify, not a row someone has to trust and clean up. There is a 12-month compatibility window if you still run DCR.

There is also a pattern worth adopting even though it is convention rather than mandate: session-scoped authorization. Instead of a standing grant, the agent’s access is approved for the duration of one task, and a new session means a new human approval. For agents that can take consequential actions, this is the difference between “the AI can touch the CRM” and “the AI could touch the CRM for that one job you approved on Tuesday.”

The honest news: where the gaps still are

The MCP maintainers are unusually candid about what the protocol does not yet solve, and their own roadmap lists the unsolved problems. These are the ones we see actually bite in production:

📜
No standard audit trail
The protocol does not define what gets logged or how it reaches your SIEM. If compliance asks “what did the agent do on March 3rd?”, the answer exists only if you engineered it yourself.
🔑
Static secrets everywhere
Long-lived client secrets in environment variables remain the most common credential pattern in real deployments — years after everyone agreed they shouldn’t be. Proper agent workload identity (proof-of-possession tokens, workload identity federation) is on the roadmap, not in the spec.
🚦
Rate limits and cost attribution
Nothing at protocol level says which team, agent, or task generated the traffic — or stops one runaway agent from consuming your API quota. The new header-based routing makes gateway-level metering feasible; it doesn’t build it for you.
🏢
Multi-tenancy isolation
If one MCP server serves many customers, keeping tenant A’s data out of tenant B’s context is entirely your architecture’s job. The protocol will not save you from a scoping bug.
The pattern across all four gaps: the protocol now secures the connection. Securing the deployment is still engineering.

Prompt injection, one year on

The other thing production experience has sharpened is how prompt injection actually shows up in MCP systems. It is rarely the movie version — a hostile hacker crafting an exploit. It is a calendar invite, a support ticket, or a scraped web page containing text that reads like instructions, sitting in data your agent was legitimately asked to process. The defence has three layers, and all three have to exist: permission boundaries so the worst case of a hijacked agent is bounded (read-only where possible, scoped to specific records where possible); output and action filtering so consequential operations are structurally separated from content the model read; and human confirmation on actions that move money, delete data, or send communications. Sixty seconds of a human’s attention is still the cheapest security control in the stack.

What a real MCP security review covers

When we review an MCP integration before go-live — ours or someone else’s — the checklist is unglamorous and specific:

1
Auth against the current spec
Resource indicators enforced, issuer validation on, CIMD migration planned if DCR is present. A build on 2025-era auth is a finding, not a preference.
2
Permission inventory per tool
Every exposed tool listed with what it can read, what it can write, and why. The commonest finding in reviews: a server exposing five write actions when the use case needed one.
3
Injection path walkthrough
Trace every source of external text the agent reads, and what the worst plausible instruction hidden in it could accomplish given the current permission set. This exercise regularly changes the permission set.
4
Audit, secrets, and blast radius
Action logging that reaches somewhere durable; credentials that rotate; and a written answer to “what happens if this one credential leaks?” per credential.

Related: the application-level version of these controls, cost control and prompt injection for AI features in a vibe-coded app.


None of this argues against connecting AI to your systems — the value case we made in Integrating LLMs Beyond the Hype has only strengthened as the tooling matured. It argues for treating an MCP deployment like what it is: a production system with a new kind of user. The same rigour we apply in our 12-point production audit applies here, with the four checks above added on top.

Connecting AI to systems that matter?

We build and review MCP integrations with the permission model, audit trail, and approval gates production actually requires — and we’ll tell you honestly which of your systems shouldn’t be connected at all.

Talk to Our Team →

Engineering Insights

Latest from Syntaxa Studio.

Loading latest posts