04:25
2026-05-22
dev.to
cybersecurity
MCP SEP-2468: RFC 9207 Iss Parameter for OAuth Mix-Up Defense
MCP SEP-2468, merged into the Model Context Protocol specification on May 17, 2026, implements RFC 9207's `iss` parameter to defend against OAuth mix-up attacks. The change requires authorization servβ¦