← Browse

World's Fair 2025

Building Protected MCP Servers — Den Delimarsky and Julia Kasper, MCP Steering Committee & Microsoft

Den Delimarsky , Julia Kasper , MCP Steering Committee

Overview

This talk addresses the critical need for security in Multi-Call Protocol (MCP) servers, particularly for remote instances. It introduces a new draft specification that simplifies authorization by separating the MCP server's role from that of an authorization server. This approach aims to reduce the burden on developers by allowing them to leverage existing OAuth 2.0 libraries and identity providers, rather than implementing complex authorization logic themselves.

Who should watch

Key takeaways

Notable quotes

*The MCP client is responsible for completing this entire o dance where the server now doesn't actually need to manage tokens. You only need to make sure that you're validating them.*
*We want to make it easier as well so we know the similarities between MCP servers and APIs so one of the latest announcements that we have done is you can now also start transforming your REST APIs into remote MCP servers using our tools.*

Watch on YouTube →

Unofficial community note. Prefer the recording for nuance.