The introduction of LLMs, AI agents, and their evolving ecosystem of tooling like Model Context Protocol (MCP) has opened the doors to a variety of new use cases. Still, they present unique challenges to secure in production, leaving us with many unanswered questions about how we will create safe and secure applications for our users.
I encountered some of those questions when our team first began exploring MCP and its applications. We asked ourselves questions like, “The MCP spec doesn’t say exactly what we should do for auth… so how…