How to use this reference
Map operations to permissions, issue focused challenges, support reduced grants and record elevations. Review initial discovery and subsequent consent together; do not assume every authorization request represents only the current operation.
Before reading
- OAuth scope and consent concepts; client/server authorization responsibilities
Context and limits
- The guide permits several challenge-breadth strategies. When an initial challenge omits scope, it documents requesting all advertised scopes; it does not universally require the narrowest request.
- Maintained guidance, not evidence of a specific deployment’s exposure or a verified patch. Publication and edition dates remain unknown; the URL version is preserved separately.
Sources and provenance
- Security Best Practices: Scope Minimization Model Context Protocol · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.