Fetching from the wire…
Public story · 2026-02-23 · source-backed
Astrix analysis of 5,000+ open-source MCP servers: 53% rely on static API keys, only 8.5% implement OAuth. The MCP spec now supports OAuth 2.1 with PKCE and .well-known/oauth-protected-resource discovery. Five risk domains: authentication gaps, supply chain weaponization, privilege escalation via unscoped tokens, confused deputy attacks, and data exfiltration via trusted channels.
Builder action: Implement OAuth 2.1 with PKCE for all production MCP servers. Use short-lived tokens (5-30 min). Static API keys in MCP servers are the equivalent of storing passwords in plaintext. The tooling exists — adoption is the bottleneck.
Source: Bitdefender | Astrix
Each link below shares sources, entities, or timing with this story.
MCP uses OAuth / Shared entities / Same source / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses OAuth); both cover Bitdefender, Builder, MCP, OAuth; cite the same source (Bitdefender).
MCP uses OAuth / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (MCP uses OAuth); both cover Builder, MCP; overlapping topics (attack, builder, chain, server).
MCP uses OAuth / Shared entities / Same source domain / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Bitdefender, MCP; reported by the same outlet (businessinsights.bitdefender.com).
MCP uses OAuth / Shared entities / Same source / Earlier coverage
Linked by a graph relationship (MCP uses OAuth); both cover Bitdefender, MCP; cite the same source (Bitdefender).
MCP uses OAuth / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover MCP, OAuth; overlapping topics (attack, chain, keys).
Linked by a graph relationship (MCP uses OAuth); both cover MCP, OAuth; overlapping topics (keys, server, token).
Linked by a graph relationship (MCP uses OAuth); both cover MCP, OAuth; overlapping topics (authentication, oauth, server).
Linked by a graph relationship (MCP uses OAuth); both cover MCP, OAuth; overlapping topics (server, static, token).