Token passthrough

The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it. The MCP specification forbids it: a server must not accept any token not explicitly issued for it, and so checks each token's audience 1.

Developed in
ch. 23, MCP authorization as of 2026-07-28
Chapters
ch. 23, AI Agents
Contrast with
Delegation (OAuth token exchange)
Source
1 numbered reference, listed below

Where it is used

One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.

Sources

  1. [1] Model Context Protocol, Security Best Practices, version 2026-07-28 (token passthrough defined and explicitly forbidden; servers MUST NOT accept any tokens not explicitly issued for them; audience validation). Model Context Protocol. 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Token passthrough. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/token-passthrough. CC BY 4.0

BibTeX

@misc{aige2026tokenpassthrough,
  author  = {Jorge García Aibar},
  title   = {{Token passthrough}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/token-passthrough}
}