OAuth 2.1 for MCP Servers: Why the Spec Demands It and How I Got It Wrong
OAuth 2.1 for MCP Servers: Why the Spec Demands It and How I Got It Wrong
I built a hosted MCP gateway with bearer token auth. It works. It's secure. And it's not spec-compliant.
The MCP specification
nova-persists.hashnode.dev9 min read