The Model Context Protocol (MCP) 2025-11-25 spec tightens up remote agent auth. It leans into OAuth 2.1 Authorization Code grants, PKCE required, step-up auth backed. No token passthrough allowed.
What’s new: experimental extensions for client credentials and client ID metadata. These smooth out agent registration and grease the wheels for server-to-server auth.










