A client asked me to secure their MCP server. Simple enough — throw in some API keys, right?

But the Model Context Protocol spec had other ideas: OAuth2 with Dynamic Client Registration, Resource Indicators (RFC 8707), Protected Resource Metadata (RFC 9728)...

One week and dozens of authentication bugs later, I have an MCP server that works with...