Free tools Windows power users keep installed
One-click scans. No signup required.
MCP authorization is OAuth for protected resources. An MCP client discovers which authorization server can issue a token, obtains authorization, and presents that token to the MCP server. The server must then verify that the token is intended for that specific resource—not merely that the signature or issuer is valid. The MCP specification released on July 28, 2026, adds stricter issuer checks, binds client credentials to the issuer that created them, and makes Client ID Metadata Documents (CIMD) the preferred registration approach.
How does MCP authorization work?
MCP authorization protects a remote server and the data or actions behind its tools. The normal flow is:
- The client requests protected-resource metadata. The MCP server publishes
/.well-known/oauth-protected-resource. This document identifies the resource and the authorization server or servers that may issue tokens for it. - The client reads authorization-server metadata. At
/.well-known/oauth-authorization-server, the authorization server advertises its authorization and token endpoints, supported scopes, and whether it supports CIMD. - The client registers or identifies itself. CIMD is now the preferred direction. Older deployments may still use Dynamic Client Registration (DCR) for compatibility.
- The user or administrator authorizes access. The client sends the user to the authorization endpoint with the required redirect URI, client identifier, resource and scopes.
- The client validates the response issuer. Before exchanging an authorization code, clients must validate the authorization response’s
issvalue. This check, required by the July 28, 2026 release, prevents an authorization-server mix-up. - The client exchanges the code for a token. Credentials stored for one issuer must not be reused with another issuer. The token request is sent to the endpoint advertised by the selected authorization server.
- The MCP server validates the token for its resource. Signature and issuer checks are necessary, but insufficient. The resource server must also verify that the token was issued for the intended MCP resource and that its privileges are acceptable.
A valid identity-provider token does not automatically authorize every MCP server. Resource-specific audience or resource checks are part of the security boundary.
What the discovery documents tell a client
| Document | Path | Purpose |
|---|---|---|
| Protected Resource Metadata | /.well-known/oauth-protected-resource |
Identifies the protected resource and one or more authorization servers that can issue tokens for it. |
| Authorization Server Metadata | /.well-known/oauth-authorization-server |
Advertises authorization and token endpoints, supported scopes, and CIMD support. |
How do I add permissions to an MCP server?
Permissions are added by combining OAuth policy with enforcement inside the MCP server. The protocol does not make a token trustworthy merely because an identity provider signed it.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Read Before You Buy — No Video Output: These adapters support charging and USB 2.0 data transfer, but cannot transmit video signals. Except for standard USB webcams (which use USB data only), they are not compatible with HDMI/DisplayPort cables, video-capable USB-C hubs, or docking stations with video output.
- Convert USB-A Ports to USB-C: Designed to connect USB-C earphones, cables, flash drives, card readers, and other USB-C accessories to standard USB-A ports. Plug-and-play with no drivers or software required.
- Aluminum Alloy Housing: Built with a sturdy aluminum alloy shell that aids in heat dissipation and protects against daily wear and scratches. Designed to maintain a stable and secure connection.
- Compact & Travel-Friendly: The ultra-compact design allows the adapter to stay plugged into your device without blocking adjacent ports or adding bulk, reducing wear and tear on your original USB ports.
- 12-Month Warranty: Backed by a 12-month manufacturer warranty for peace of mind. Designed to meet strict quality control standards for reliable everyday performance.
- Define the protected resource. Use the canonical MCP server URL or resource identifier that tokens must target. Keep this value stable; resource validation fails when clients request a token for a different identifier.
- Publish protected-resource metadata. Serve
/.well-known/oauth-protected-resourceover HTTPS and list every authorization server that is actually accepted. - Configure the authorization server. Publish authorization-server metadata, register supported redirect URIs, and expose only the scopes your server can enforce.
- Choose registration. Implement CIMD when both the client and authorization server support it. Retain DCR only where existing clients require it; the July 28, 2026 specification formally deprecates DCR and plans to remove it in a future version.
- Validate authorization responses. Compare the response
issvalue with the issuer selected from discovery before redeeming a code. - Bind credentials to the issuer. Store the issuer alongside client credentials. Never send credentials created by one authorization server to another server that happens to protect a different MCP resource.
- Validate every access token. Check signature, issuer, expiry, resource or audience, and the permissions your server understands. Reject tokens that are valid JWTs but intended for another resource.
- Enforce permissions at execution time. Before invoking a tool or downstream API, verify the caller’s effective permission and apply argument-level restrictions where your design requires them.
Discovery smoke test
After deploying metadata, test both documents from a shell. Set the real server origin in an environment variable, then run:
export MCP_RESOURCE_URL='https://mcp.example.com'
curl --fail --silent --show-error "$MCP_RESOURCE_URL/.well-known/oauth-protected-resource"
curl --fail --silent --show-error "$MCP_RESOURCE_URL/.well-known/oauth-authorization-server"
Confirm that the first response names the resource and an issuer, and that the second response contains authorization and token endpoints. If the resource lists multiple issuers, the client must select one it supports and apply issuer checks consistently.
How do MCP OAuth scopes work?
OAuth scopes are strings carried through authorization and token issuance, but MCP does not guarantee a universal one-scope-per-tool mapping. A February 17, 2026 tool-scopes working-group record said that defining, managing and challenging tool scopes still lacked standardized guidance. Implementations may map scopes to servers, tools, arguments or downstream APIs, and a mapping may depend on tool arguments.
Rank #2
- 5-in-1 USB-C Hub: Experience comprehensive connectivity featuring a Power Delivery input, two USB-A 2.0 ports, a USB-A 3.0 port, and an HDMI port. (Note: The USB-C power delivery input port is only for connecting an external wall charger to power your laptop and cannot power peripheral devices.)
- 90W Pass-Through Charging: Achieve optimal charging with 90W pass-through power to your laptop, supported by a total input of 100W, with the hub reserving 10W for operational efficiency. (Note: Wall charger not included.)
- Quick Data Transfers: Accelerate your productivity with rapid data transfers using a high-speed 5Gbps USB 3.0 port and two 480Mbps USB 2.0 ports.
- 4K HDMI Display: Enhance your visual experience with a hub capable of delivering 4K resolution at 30Hz in both mirror and extend modes. Please note that this hub is compatible with MacBook (macOS 12 and newer), Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
- What You Get: Anker USB-C Hub (5-in-1, 4K HDMI), welcome guide, 18-month warranty, and our friendly customer service.
| Permission boundary | What it can control | Implementation question |
|---|---|---|
| Server | Whether the client may connect to the MCP resource. | Does any valid token for this resource permit a session, or is a server scope required? |
| Tool | Whether a named tool may be called. | Does the server enforce a distinct scope, role or policy before dispatch? |
| Argument | Whether particular records, tenants, actions or parameter values are allowed. | Are restrictions evaluated from claims, groups, tool arguments or a policy engine? |
| Downstream API | What the MCP server may do on the user’s behalf elsewhere. | Is a separate token, delegated permission or service policy required? |
Document your mapping for clients and administrators. Do not tell users that an OAuth scope automatically grants or denies a tool unless your server actually enforces that rule. Also define the behavior when a tool needs more privilege: return an authorization error, request a new consent step, or deny the operation according to the policy your identity provider and server support. The exact scope-accumulation and step-up algorithm in the July 28, 2026 specification is not established by the implementation material summarized here, so verify the normative text before implementing one.
How do MCP clients discover the authorization server?
Discovery is resource-first. A client begins with the MCP server it wants to use, retrieves Protected Resource Metadata, and follows the listed issuer to Authorization Server Metadata. This prevents a client from guessing an issuer or sending credentials to an unrelated identity provider.
CIMD versus DCR
Under CIMD, the client identifier is a URL for a document describing the client. The authorization server does not need to host a client-registration endpoint for that client description. DCR remains available for backward compatibility, but the 2026-07-28 release marks it as deprecated and says it is planned for removal in a future specification version. The deployment’s metadata and registration policy determine which method is usable.
Rank #3
- Sleek 7-in-1 USB-C Hub: Features an HDMI port, two USB-A 3.0 ports, and a USB-C data port, each providing 5Gbps transfer speeds. It also includes a USB-C PD input port for charging up to 100W and dual SD and TF card slots, all in a compact design.
- Flawless 4K@60Hz Video with HDMI: Delivers exceptional clarity and smoothness with its 4K@60Hz HDMI port, making it ideal for high-definition presentations and entertainment. (Note: Only the HDMI port supports video projection; the USB-C port is for data transfer only.)
- Double Up on Efficiency: The two USB-A 3.0 ports and a USB-C port support a fast 5Gbps data rate, significantly boosting your transfer speeds and improving productivity.
- Fast and Reliable 85W Charging: Offers high-capacity, speedy charging for laptops up to 85W, so you spend less time tethered to an outlet and more time being productive.
- What You Get: Anker USB-C Hub (7-in-1), welcome guide, 18-month warranty, and our friendly customer service.
Desktop and command-line clients
The July 28 release also says clients set application_type during DCR so authorization servers correctly handle desktop and command-line clients that use localhost redirect URIs. A correct value does not override the authorization server’s redirect-URI policy; inspect the server’s registration rules when a redirect is rejected.
What security checks changed in the July 28, 2026 MCP release?
- Authorization-response issuer validation: clients must validate
issbefore redeeming an authorization code, addressing authorization-server mix-up attacks. - Issuer-bound credentials: credentials are tied to the authorization server that issued them and must not be reused for another issuer.
- CIMD preference: CIMD is the forward-looking registration method; DCR is retained only for compatibility.
- Resource-specific validation remains mandatory: a token’s signature or issuer alone does not prove that it was minted for your MCP resource.
How do I manage MCP access across an enterprise?
For individual use, a client normally sends each user through an interactive OAuth consent flow. Enterprise-Managed Authorization (EMA) instead lets an organization make its identity provider the central decision-maker for MCP server access. Administrators can provision and revoke access, apply group- and role-based policies, enforce conditional-access rules and maintain an audit trail.
| Question | Individual OAuth | Enterprise-Managed Authorization |
|---|---|---|
| Who decides access? | The user and the authorization server’s consent and policy. | The organization’s identity provider and administrator policies. |
| How is access provisioned? | User-by-user authorization. | Central policy based on groups, roles and conditions. |
| How are accounts separated? | Depends on the user’s selected account. | Central controls reduce accidental mixing of personal and work accounts. |
| What must be verified? | OAuth endpoints, scopes and token-resource validation. | All of those, plus exact identity-provider, MCP client and server support for EMA. |
The June 18, 2026 EMA launch announcement identified Okta as the first supported identity provider and listed Anthropic and Visual Studio Code as supporting clients. It named Asana, Atlassian, Canva, Figma, Granola, Linear and Supabase among server adopters, with Slack and others adding support at that time. This was a launch snapshot, not a current compatibility guarantee; verify support for the precise client, server and identity-provider versions you operate.
Rank #4
- Dual Converters, Infinite Potential:Includes 2× USB C male to USB A female adapters and 2× USB A male to USB C female adapters. Perfect for a wide range of uses—tablets with Bluetooth keyboards, expand USB ports on macbook, and more. Two different converters for all your daily needs
- Next-Level 10Gbps & 3A Charging: No more slow 480Mbps, this usb to usb c adapter has a transfer speed of up to 10Gbps, allowing you to do more transferring in less time. This usb adapter fits both USB A and USB C charger, supporting up to 3A fast charging
- Upgraded Exquisite Craftsmanship: With an aluminum alloy housing and metal connector, the usbc to usb adapter is extremely durable and sturdy. Rigorously tested to withstand more than 10,000 times of plugging and unplugging, ensuring long-lasting performance
- Broad Compatible: The usb c to usb adapter widely supports all USB C/ USB A devices like laptops, tablets, cellphones, car chargers, and phone chargers. Such as compatible with MacBook Pro/Air 2023/2022, Thunderbolt 4/3 Devices,Apple MagSafe Watch 9/8/7/SE/Ultra, iPad Pro 2022/2021, Samsung Galaxy S23/S20/S10, and iPhone 17/16/15 Pro. Plug and play
- Please Note: To reach 10Gbps speed, keep the cable under 3.3 ft. For USB A Male to USB C adapters, try flipping the USB C connector. USB C Male to USB A adapters support bidirectional 10Gbps transfer within 3.3 ft
Troubleshooting MCP authorization
| Symptom | Likely cause | Fix |
|---|---|---|
| Client cannot find an issuer | Protected Resource Metadata is missing, malformed or unreachable. | Serve /.well-known/oauth-protected-resource over HTTPS and include the correct issuer URL. |
| Authorization code exchange fails after a successful login | The response issuer was not validated or does not match the selected issuer. | Compare iss before redemption and restart discovery when issuers change. |
invalid_client or redirect URI error |
Registration method, client credentials or redirect URI does not match server policy. | Check whether CIMD or DCR is supported, set application_type for desktop or CLI DCR clients, and register the exact redirect URI. |
| JWT signature verifies but the server returns unauthorized | The token is for another resource or lacks an enforced permission. | Inspect audience/resource claims and the server’s scope or policy mapping; do not weaken resource validation. |
| Works with one issuer but not another | Client credentials were reused across authorization servers. | Keep credentials and issuer metadata together and obtain credentials from the active issuer. |
| A tool call is accepted despite a supposedly missing scope | The implementation never mapped that scope to the tool or argument. | Inspect dispatch and downstream policy enforcement. MCP does not supply a universal tool-scope mapping. |
Implementation checklist
- Identify the canonical MCP resource identifier.
- Publish Protected Resource Metadata and Authorization Server Metadata.
- Use HTTPS and exact redirect-URI matching.
- Prefer CIMD; keep DCR only for clients that need backward compatibility.
- Validate authorization-response
issbefore code redemption. - Bind each client credential to its issuing authorization server.
- Validate token signature, issuer, expiry and resource or audience.
- Document where permissions are enforced: server, tool, argument and downstream API.
- Test denied access, expired tokens, wrong-resource tokens and issuer changes.
- For enterprises, verify EMA support and audit behavior across the exact IdP, client and MCP server combination.
Or skip the browser setup
If your workflow needs screenshots as part of an MCP-enabled agent, ScreenshotNeo provides an MCP server with take_screenshot, get_page_info and capture_pdf tools. Its HTTP API uses an access key; configure that credential according to your organization’s policy rather than assuming it participates in your MCP OAuth scopes.
One request returns a PNG, JPEG, WebP or PDF. ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups and chat widgets before capture; each step can be disabled. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and the response identifies the page verdict and billing status in X-Page-Verdict and X-Billed headers.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for all request options. The same call from Python is:
Recommended Free Tools
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
ScreenshotNeo includes full-page and element capture, device and viewport controls, retina scale, PDF settings, custom CSS and JavaScript, waits, request blocking, headers, cookies, user agents, authorization, geolocation, timezone, resizing, caching, signed links, asynchronous webhooks, bulk capture of up to 100 URLs per call, a usage API and an OpenAPI specification. Its Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
Best Value
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
Frequently Asked Questions
Can one MCP resource trust more than one authorization server?
Yes. Protected Resource Metadata can identify multiple issuers. The client must choose a supported issuer, validate the response issuer, and keep credentials bound to that issuer.
Is a JWT audience check optional when the signature is valid?
No. The MCP resource still has to verify that the token was issued for it; signature and issuer validation alone are incomplete.
Should an enterprise assume every MCP client supports EMA?
No. EMA support depends on the exact identity provider, MCP client and server. Confirm compatibility and policy behavior for the versions you deploy.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

