Authorization is formally optional in MCP. That wording misleads people. It means you may run an unprotected server; it does not mean you get to half-implement a protected one. The moment you do protect an HTTP transport, the spec fills up with MUSTs, and most teams meet maybe half of them: pull in a library, wire up a login, ship it, leave three... Weiterlesen
Intelligence View
OAuth 2.1 for MCP servers, done properly
Authorization is formally optional in MCP. That wording misleads people. It means you may run an unprotected server; it does not mean you get to half-implement a protected one. The moment you do protect an HTTP transport, the spec fills up…
SOCIAL SHARE CARD GENERATOR