HD Field Guide 10
MCP security before you connect
A practical MCP review covering authorization, token audience, servers, tools, consent, logs and revocation.
Control areaApplications
AudienceDevelopers & security teams
Reading time8 min
Reviewed11 August 2026
MCP makes external capability easy to connect. That convenience must not be mistaken for trust.
Treat MCP as an API security boundary
Validate authorization, tool input and access as you would for privileged APIs.
Do not pass access tokens through to downstream services.
Make consent meaningful
Show users what the tool can access or change.
Require confirmation for sensitive operations.
Before you close the guide
- Server approved
- Authorization validated
- Tools constrained
- Logs and revocation available
Continue with primary guidance
Defensive guidance boundary
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.