This is a scoped research dossier, not a completed systematic review or an independently tested result. It identifies methods, questions and source trails for future reporting.
Read a tool contract
The MCP specification gives tools a name, schema and invocation protocol; descriptions and metadata do not replace independent permission enforcement.
Authorization at the boundary
A server needs to validate each operation against the caller’s real scope. An agent’s generated rationale is not an authorization token.
Version the integration
Protocol editions evolve. We record specification dates, SDK versions and gateway behavior alongside any reported result.
What would count as evidence?
Publish exact tool manifest, auth scope, expected errors and denied-call traces.
Documents to examine
- MCP 2026 Tools Specification
- MCP 2026 Authorization Specification
These are starting points, not claims that every document has been independently reproduced.
Read our cited field note →Edition 1.0 · 09 October 2026
Initial research brief published. No earlier revisions or submitted public corrections are claimed.
Suggest a documented correction ↗