Securing MCP in Production: OAuth, Agent Identity, and What a 2026 Security Review Actually Covers
The protocol’s auth story has matured fast. The gaps that actually hurt companies in production are mostly somewhere else — here is where we look.
When we explained MCP for business readers, we flagged two risks vendors gloss over: prompt injection and over-permissioning. Both still matter. But a year of production deployments — and two major specification releases — have made the security picture much more specific. This post is the deeper cut: what the protocol now handles for you, what it deliberately leaves to you, and the review we run before an MCP integration touches real customer data.
The good news first: MCP auth grew up
Early MCP deployments handled authorization with whatever the integrator improvised. That era is over. Three changes, rolled out across the 2025–2026 spec releases, closed the most dangerous protocol-level gaps:
There is also a pattern worth adopting even though it is convention rather than mandate: session-scoped authorization. Instead of a standing grant, the agent’s access is approved for the duration of one task, and a new session means a new human approval. For agents that can take consequential actions, this is the difference between “the AI can touch the CRM” and “the AI could touch the CRM for that one job you approved on Tuesday.”
The honest news: where the gaps still are
The MCP maintainers are unusually candid about what the protocol does not yet solve, and their own roadmap lists the unsolved problems. These are the ones we see actually bite in production:
Prompt injection, one year on
The other thing production experience has sharpened is how prompt injection actually shows up in MCP systems. It is rarely the movie version — a hostile hacker crafting an exploit. It is a calendar invite, a support ticket, or a scraped web page containing text that reads like instructions, sitting in data your agent was legitimately asked to process. The defence has three layers, and all three have to exist: permission boundaries so the worst case of a hijacked agent is bounded (read-only where possible, scoped to specific records where possible); output and action filtering so consequential operations are structurally separated from content the model read; and human confirmation on actions that move money, delete data, or send communications. Sixty seconds of a human’s attention is still the cheapest security control in the stack.
What a real MCP security review covers
When we review an MCP integration before go-live — ours or someone else’s — the checklist is unglamorous and specific:
Related: the application-level version of these controls, cost control and prompt injection for AI features in a vibe-coded app.
None of this argues against connecting AI to your systems — the value case we made in Integrating LLMs Beyond the Hype has only strengthened as the tooling matured. It argues for treating an MCP deployment like what it is: a production system with a new kind of user. The same rigour we apply in our 12-point production audit applies here, with the four checks above added on top.
Connecting AI to systems that matter?
We build and review MCP integrations with the permission model, audit trail, and approval gates production actually requires — and we’ll tell you honestly which of your systems shouldn’t be connected at all.
