571 pages for author.
Titles and paths first, then pages whose text carries it. Each row opens that page as this site last read it.
Architecture
Model Context Protocol · in the page
specification/2026-07-28/architecture/index
…* Enforces security policies and consent requirements * Handles user authorization decisions * Coordinates AI/LLM integration and sampling * Manages context aggregation across clients ### Clients E…
Overview
Model Context Protocol · in the page
specification/2026-07-28/basic/index
…ponse, multi round-trip requests (MRTR), and subscribe and notify * **Authorization**: Authentication and authorization framework for HTTP-based transports * **Server Features**: Resources, prompts, a…
Multi Round-Trip Requests
Model Context Protocol · in the page
specification/2026-07-28/basic/patterns/mrtr
…tState` as an attacker-controlled input. If `requestState` influences authorization, resource access, or business logic, servers **MUST** protect its integrity (e.g. HMAC or AEAD) and **MUST** reje…
Key Changes
Model Context Protocol · in the page
specification/2026-07-28/changelog
…to `-32602` (Invalid Params) to align with JSON-RPC specification. 7. Authorization servers **SHOULD** include the `iss` parameter in authorization responses per [RFC 9207](https://datatracker.ietf…
Elicitation
Model Context Protocol · in the page
specification/2026-07-28/client/elicitation
…this context refers to secrets and credentials that grant access or authorize transactions. General contact or profile information (such as a name, email address, or username) is not categorically…
Deprecated Features
Model Context Protocol · in the page
specification/2026-07-28/deprecated
…-28 | | [Dynamic Client Registration](/specification/2026-07-28/basic/authorization/client-registration#dynamic-client-registration) | [PR #2858](https://github.com/modelcontextprotocol/modelcontextpr…
Specification
Model Context Protocol · in the page
specification/2026-07-28/index
…nect LLMs with the context they need. This specification defines the authoritative protocol requirements, based on the TypeScript schema in [schema.ts](https://github.com/modelcontextprotocol/specifi…
Prompts
Model Context Protocol · in the page
specification/2026-07-28/server/prompts
…for use. This refers to who decides when the prompt is used, not who authors its content. Prompt content is defined by the server. Typically, prompts would be triggered through user-initiated comman…
Resources
Model Context Protocol · in the page
specification/2026-07-28/server/resources
…fect of other requests on the connection. The set **MAY** vary by the authorization presented on the request — for example, returning only the resources the caller's granted scopes permit — since cred…
Tools
Model Context Protocol · in the page
specification/2026-07-28/server/tools
…fect of other requests on the connection. The set **MAY** vary by the authorization presented on the request — for example, returning only the tools the caller's granted scopes permit — since credenti…
Caching
Model Context Protocol · in the page
specification/2026-07-28/server/utilities/caching
…ared between callers. Cached responses **MAY** be reused for the same authorization context. Caches **MUST NOT** be shared across authorization contexts (e.g. a different access token requires a diffe…
Architecture
Model Context Protocol · in the page
specification/draft/architecture/index
…* Enforces security policies and consent requirements * Handles user authorization decisions * Coordinates AI/LLM integration and sampling * Manages context aggregation across clients ### Clients E…
Overview
Model Context Protocol · in the page
specification/draft/basic/index
…ponse, multi round-trip requests (MRTR), and subscribe and notify * **Authorization**: Authentication and authorization framework for HTTP-based transports * **Server Features**: Resources, prompts, a…
Multi Round-Trip Requests
Model Context Protocol · in the page
specification/draft/basic/patterns/mrtr
…tState` as an attacker-controlled input. If `requestState` influences authorization, resource access, or business logic, servers **MUST** protect its integrity (e.g. HMAC or AEAD) and **MUST** reje…
Elicitation
Model Context Protocol · in the page
specification/draft/client/elicitation
…this context refers to secrets and credentials that grant access or authorize transactions. General contact or profile information (such as a name, email address, or username) is not categorically…
Deprecated Features
Model Context Protocol · in the page
specification/draft/deprecated
…27-07-28 | | [Dynamic Client Registration](/specification/draft/basic/authorization/client-registration#dynamic-client-registration) | [PR #2858](https://github.com/modelcontextprotocol/modelcontextpr…
Specification
Model Context Protocol · in the page
specification/draft/index
…nect LLMs with the context they need. This specification defines the authoritative protocol requirements, based on the TypeScript schema in [schema.ts](https://github.com/modelcontextprotocol/specifi…
Prompts
Model Context Protocol · in the page
specification/draft/server/prompts
…for use. This refers to who decides when the prompt is used, not who authors its content. Prompt content is defined by the server. Typically, prompts would be triggered through user-initiated comman…
Resources
Model Context Protocol · in the page
specification/draft/server/resources
…fect of other requests on the connection. The set **MAY** vary by the authorization presented on the request — for example, returning only the resources the caller's granted scopes permit — since cred…
Tools
Model Context Protocol · in the page
specification/draft/server/tools
…fect of other requests on the connection. The set **MAY** vary by the authorization presented on the request — for example, returning only the tools the caller's granted scopes permit — since credenti…
Caching
Model Context Protocol · in the page
specification/draft/server/utilities/caching
…ared between callers. Cached responses **MAY** be reused for the same authorization context. Caches **MUST NOT** be shared across authorization contexts (e.g. a different access token requires a diffe…