vulns.co
/
GKData.io MCP

Model Context Protocol · 1 min read

MCP elicitation: consent, credential custody and completion

Form elicitation excludes secrets. URL elicitation places sensitive interactions outside the MCP client and model context, with the requesting server and destination visible to the user. Agreeing to open the interaction is not completion evidence; the server determines completion separately. For third-party OAuth, the MCP server holds the resulting credentials; this grant is separate from the client's authorization to access that server.

Open the reference Technical StandardReviewed 2026-10-04

How to use this reference

Editorial guidance: map the data recipient, credential holder and authoritative completion evidence for each interaction. Preserve decline and cancellation, bind completion to the initiating identity, and review navigation consent and automatic URL handling independently.

Before reading

  • MCP client/server roles, OAuth delegation and credential storage

Context and limits

  • The form prohibition concerns access or transaction secrets; ordinary contact data is not categorically excluded.
  • Elicitation prohibits automatic URL or metadata prefetching and navigation without explicit consent. It requires the full URL to be shown and credentials to stay out of URLs.
  • The overview states that protocol rules alone cannot enforce its security principles; implementation controls remain necessary.
  • No deployed vulnerability, remediation or award is established. The URL version is preserved separately from unknown publication and release dates.

Sources and provenance

  1. Elicitation Model Context Protocol · reviewed 2026-10-04
  2. Specification: Security and Trust & Safety Model Context Protocol · reviewed 2026-10-04

Record reviewed 2026-10-04. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software