---
title: "Token passthrough"
description: "The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it."
canonical: https://aigovernanceengineer.com/glossary/token-passthrough
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Token passthrough

The anti-pattern in which a server accepts a token that was not issued to it and forwards it, unmodified, to a downstream API, which may then trust it as if the server had validated it. The MCP specification forbids it: a server must not accept any token not explicitly issued for it, and so checks each token's audience [1].

- Developed in: [ch. 23, MCP authorization as of 2026-07-28](https://aigovernanceengineer.com/bok/governing-agents#mcp-authorization-as-of-2026-07-28)
- Chapters: [ch. 23, AI Agents](https://aigovernanceengineer.com/bok/governing-agents)
- Contrast with: [Delegation (OAuth token exchange)](https://aigovernanceengineer.com/glossary/delegation-oauth-token-exchange)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-token-passthrough

## Sources

[1] Model Context Protocol, Security Best Practices, version 2026-07-28 (token passthrough defined and explicitly forbidden; servers MUST NOT accept any tokens not explicitly issued for them; audience validation). Model Context Protocol. 2026-07-28. https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices (verified: primary)
