We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent cfdfc11 commit bd41226Copy full SHA for bd41226
docs/specification/draft/basic/authorization.mdx
@@ -299,7 +299,7 @@ See [Security Best Practices 2.1](/specification/draft/basic/security_best_pract
299
MCP proxy servers using static client IDs **MUST** obtain user consent for each dynamically
300
registered client before forwarding to third-party authorization servers (which may require additional consent).
301
302
-### 3.5 Access Token Privilege Restriction
+### 3.6 Access Token Privilege Restriction
303
304
An attacker can gain unauthorized access or otherwise compromise a MCP server if the server accepts tokens issued for other resources.
305
0 commit comments