Source-backed facts for citing this resource, derived directly from the registry — also available as plain text for AI assistants.
- Source URLs
- https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization, https://github.com/JSONbored/awesome-claude/blob/main/content/guides/mcp-protected-resource-metadata-verification-guide.mdx
- Safety notes
- Never send a production user token to an MCP server until the resource metadata and token audience have been verified., Treat token passthrough, missing resource indicators, or acceptance of tokens issued for another resource as release-blocking., Do not paste bearer tokens into prompts, PR comments, issue comments, screenshots, or public logs while debugging MCP auth.
- Privacy notes
- Authorization metadata can reveal tenant URLs, identity providers, scopes, client registration behavior, and internal endpoint names., Verification traces may include redirect URLs, state parameters, token claims, account IDs, or workspace identifiers; redact them before public sharing.
- Author
- JSONbored
- Submitted by
- JSONbored
- Claim status
- unclaimed
- Last verified
- 2026-06-05