Add "What the MCP spec left out" under a new Reading section#196
Draft
wkoverfield wants to merge 2 commits into
Draft
Add "What the MCP spec left out" under a new Reading section#196wkoverfield wants to merge 2 commits into
wkoverfield wants to merge 2 commits into
Conversation
…n card The essay states what the 2026-07-28 MCP revision standardizes, the three absences in its core (runtime authorization, sub-agent delegation, audit), the reliability case for delegation, the seven invariants a delegation layer needs with their RFC 8693 mapping, and the routed-paths enforcement boundary. Published under a new Reading section; the landing delegation card links to it. Publishes with the 2026-07-28 specification release. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
docs/product/what-the-spec-left-out.md, registered on the docs site under a new Reading section, and links it from the landing delegation card.The essay covers: what the 2026-07-28 MCP revision standardizes (OAuth 2.1 resource servers, mandatory Protected Resource Metadata and Resource Indicators), the three absences in its core (runtime authorization, sub-agent delegation, audit), the reliability case for bounded delegation, seven invariants with their RFC 8693 mapping, and the honest routed-paths enforcement boundary.
Held as a draft to publish with the 2026-07-28 specification release. Before merge: verify every spec claim against the final published text, since this is written against the release candidate.
Site build verified locally; the page renders at
/docs/what-the-spec-left-out.🤖 Generated with Claude Code