futureofagents.org
RESEARCH DOSSIER / 2026.10INITIAL EDITION · OPEN FOR REVIEW
← Back to research index

Interfaces are not permissions

Tools & Protocols.

Tool discovery, schema validation and credential scope each solve different problems.

EVIDENCE STATUS / LAUNCH

This is a scoped research dossier, not a completed systematic review or an independently tested result. It identifies methods, questions and source trails for future reporting.

01

Read a tool contract

The MCP specification gives tools a name, schema and invocation protocol; descriptions and metadata do not replace independent permission enforcement.

02

Authorization at the boundary

A server needs to validate each operation against the caller’s real scope. An agent’s generated rationale is not an authorization token.

03

Version the integration

Protocol editions evolve. We record specification dates, SDK versions and gateway behavior alongside any reported result.

SUGGESTED VERIFICATION METHOD

What would count as evidence?

Publish exact tool manifest, auth scope, expected errors and denied-call traces.

STARTING SOURCE TRAIL

Documents to examine

  • MCP 2026 Tools Specification
  • MCP 2026 Authorization Specification

These are starting points, not claims that every document has been independently reproduced.

Read our cited field note →
EDITORIAL / VERSION RECORD

Edition 1.0 · 09 October 2026

Initial research brief published. No earlier revisions or submitted public corrections are claimed.

Suggest a documented correction ↗