MCP Authentication: OAuth 2.1 Patterns for Agent Tool Access
TL;DR
* The MCP authorization specification requires OAuth 2.1, mandatory PKCE, and a strict separation between the authorization server that issues tokens and the resource server (the MCP server) that validates them.
* RFC 9728 protected resource metadata and RFC 8707 resource indicators bind an access token to one specific