First Measurement Study Reveals Widespread Authentication Failures in Remote MCP Servers
arXiv·medium signal
Researchers present the first systematic measurement of authentication security across real-world remote MCP server deployments. The study finds pervasive reliance on static API keys, long-lived tokens in config files, and missing auth on critical endpoints. As agents connect to user-linked services (social, financial, productivity), the authentication boundary between MCP clients and servers becomes the primary attack surface.