Only 8% of OAuth-advertising MCP servers meet the July 2026 security spec
A developer scanned the official MCP registry and found 2,967 servers that deliberately implemented OAuth, testing them against the 2026-07-28 authorization requirements. While legacy OAuth components scored above 92% compliance, two newly mandated features — RFC 9207 issuer identification and Client ID Metadata Documents — lagged far behind at just 19% and 23% respectively. Only 8% of the audited servers satisfied all requirements simultaneously. The failures are widely distributed across roughly 2,610 individual operators rather than concentrated among a few identity providers, meaning no single fix would resolve the gap. The author notes the 8% figure is a ceiling, not a floor, since the audit read only public metadata declarations and could not verify actual runtime behavior.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in