MCP Mandates OAuth 2.1 and PKCE in June 2025 Security Overhaul as Open Challenges Remain
MCP mandates OAuth 2.1 and PKCE in its June 2025 security overhaul, enforcing stricter authentication for remote server deployments while separating resource and authorization servers, though open challenges around scope discovery, dynamic client registration, and token error handling over SSE connections still remain.