
MCP Token Passthrough Is Dangerous
Forwarding the client’s bearer token to an upstream API erases audience boundaries and creates confused deputies.
News
Company updates, technical analysis, and focused field notes on the trust layer for multi-agent systems.

Forwarding the client’s bearer token to an upstream API erases audience boundaries and creates confused deputies.

OAuth resource parameters help ensure a token issued for one tool cannot be replayed at another.

Agents often choose tools from natural-language metadata that can redirect plans before any protected call occurs.

Discovering an authorization server is useful only if the client can prove it belongs to the intended protected resource.

When protocol features move or disappear, monitoring and authorization designs built around them can silently weaken.

Removing transport sessions improves scalability but forces systems to preserve task and principal continuity elsewhere.

Cancellation is not merely user experience; it is the mechanism that limits an autonomous plan after risk changes.

An agent may treat a tool result as fact even after it has crossed servers, summaries, memories, and other agents.