Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect an MCP server only after deciding what data and actions you are willing to expose to it. MCP standardizes how AI applications connect to tools and external context; protocol compatibility does not prove that a particular server is trustworthy. Review its tools, choose an appropriate connection method, limit permissions, enforce authorization on the server, and require approval for consequential actions.

What connecting an MCP server means for security

An MCP server can provide information to an assistant, expose tools that act on connected services, or do both. A remote server’s content can influence the model, and its tools may reach sensitive data or change state. OpenAI warns that a malicious remote MCP server could exfiltrate sensitive data that enters the model’s context. Treat the server and the content it returns as part of your trust boundary—not as safe merely because the connection uses MCP.

Prompt injection is one risk: instructions embedded in retrieved content or tool output may try to steer the assistant. The model’s stated intention to ignore those instructions is not an access-control mechanism. OAuth can authenticate and authorize a connection, but it does not prevent prompt injection or guarantee that a tool behaves safely.

Choose a connection approach for where the server runs

Deployment What to consider Practical approach
Public remote server The server is reachable over a network and may receive requests containing model context or credentials. Verify who operates it, review its tool definitions and requested access, and require appropriate authentication and server-side authorization.
Local, on-premises, or firewalled server The server may not be directly reachable by the assistant, and exposing it publicly increases its network exposure. Check whether your assistant supports a private connection method. OpenAI documents Secure MCP Tunnel for supported products to connect to private or firewalled servers without exposing them publicly or opening inbound firewall ports. Follow the current product-specific setup instructions.

Connection options vary by assistant and product. Confirm current support, transport requirements, OAuth requirements, and approval controls in the documentation for the assistant you actually use; a feature documented for OpenAI products is not a universal MCP capability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Review the server before connecting

Prefer a server whose source and maintainer you can assess and whose requested access and tool definitions are visible. There is no universal certification or safety score established for MCP servers, so evaluate the specific server and deployment rather than relying on a protocol label or friendly tool name.

  • Identify each tool’s actual effect: does it read information, write or modify data, or perform an action that is difficult to reverse?
  • Check whether the requested data and actions are necessary for your task; avoid granting broader access than needed.
  • Look for descriptions and annotations that accurately distinguish read-only tools from state-changing or destructive ones.
  • Consider what information may enter the assistant’s context and whether the server operator should be trusted with it.

Configure authentication and authorization correctly

For OAuth-protected MCP services, use the MCP authorization specification and the assistant and server’s current implementation guidance. The specification describes OAuth 2.1-based authorization, protected-resource metadata, and authorization-server discovery. Its security guidance makes token audience validation important: the server must reject a token issued for a different resource.

Rank #2
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Have the server validate credentials and authorize every request, including each tool call, against the authenticated user’s permissions.
  • Grant only the scopes and access needed for the task. Do not let the model decide whether a user is authorized.
  • Do not forward the token received from the MCP client to an upstream API. The MCP server should use an appropriate credential for that upstream service rather than treating the client’s token as a general-purpose pass-through credential.
  • Use PKCE for authorization-code exchanges where applicable; it helps reduce code interception and injection risks.

These controls constrain who can access which resources. They do not make tool output trustworthy or neutralize malicious instructions returned by a server.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Set tool limits and approval requirements in the assistant

Use the assistant’s controls to restrict available tools and require human approval for sensitive operations. Keep approval in the loop for actions such as changing records, sending messages, or deleting data when the consequences warrant it. Do not enable automatic execution of high-impact actions unless you have assessed the consequences and have effective safeguards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Tool annotations and descriptions are useful signals, not a substitute for server-side enforcement. A tool labeled “read-only” should not change state; a destructive tool should identify effects that are difficult to reverse. If the behavior does not match the description, do not grant or retain access on the strength of the label.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Connect and check the setup with low-risk tasks

  1. Review the assistant’s current MCP setup instructions. Confirm that it supports the server’s deployment and connection method, and note where its tool and approval settings are configured.
  2. Connect using the chosen method. For an OAuth-protected service, complete the authorization flow for the intended server and account. For a private server, use a supported private connection method rather than making it publicly reachable by default.
  3. Inspect the discovered tools. Compare the assistant’s tool list and descriptions with the server’s documented behavior. Disable tools that are not needed.
  4. Set access and approvals. Limit permissions to the task and require approval for consequential actions using the assistant’s available controls.
  5. Try a low-risk task first. Observe which tools the assistant invokes, what information it sends, and how it presents approval requests. A successful test can help reveal configuration problems, but it does not prove that a server is safe.

Recognize the main failure modes

  • Prompt injection: Tool output or other server content contains instructions intended to influence the model. Treat returned content as untrusted; do not assume the model will reliably resist it.
  • Overbroad or misused credentials: A server accepts a token meant for another resource or passes an MCP client token to an upstream API. Require audience validation, appropriate scopes, and no token passthrough.
  • Excessive tool authority: A connected tool can write or perform destructive actions beyond what the task requires. Restrict tools and permissions, and retain approval for sensitive operations.
  • Unnecessary network exposure: A private service is exposed directly to the internet just to make it reachable. Check for an assistant-supported private option, such as OpenAI’s documented Secure MCP Tunnel for supported products.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.