The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it. The MCP specification forbids it: a server must not accept any token not explicitly issued for it, and so checks each token's audience 1.
- Developed in
- ch. 23, MCP authorization as of 2026-07-28
- Chapters
- ch. 23, AI Agents
- Contrast with
- Delegation (OAuth token exchange)
- Source
- 1 numbered reference, listed below
Where it is used
One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.
- 23 · AI Agents Identity and short-lived credentials 3 mentions
Related terms
Sources
- [1] Model Context Protocol, Security Best Practices, version 2026-07-28 (token passthrough defined and explicitly forbidden; servers MUST NOT accept any tokens not explicitly issued for them; audience validation). Model Context Protocol. 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .