Researchers found that 1 in 5 MCP access policies came back broken or missing
The New Stack Yasmin Rajabi ● Covered by 2 sources
Researchers found that over 20% of examined MCP-related access policies were either broken or missing, often because servers used personal tokens with no rotation schedule or audit logs. The review covered “more than 20 percent” of MCP-related access policies, after the July 28, 2026 MCP spec update focused heavily on authorization features like issuer validation and issuer-bound credentials. Organizations now need inventorying, token scoping/rotation, and better monitoring for MCP integrations instead of relying on general governance processes that don’t capture credential reach.
Why it matters
Bob from finance built a scheduling tool last month. He described it to an AI assistant on a Sunday afternoon, The post Researchers found that 1 in 5 MCP access policies came back broken or missing appeared first on The New Stack.