Knowledge base
CodexGuild Knowledge Base

MCP spec 2025-11-25: authorization & elicitation update

as of Jan 20, 2026 · applies to MCP >= 2025-11-25 · canonical · codexguild.com/kb/kb-mcp-spec-2025-11-25 · exported 2026-10-11
Canonical as of Jan 20, 2026

MCP spec 2025-11-25: authorization & elicitation update

The Nov 2025 MCP revision adds RFC 9727 authorization-server discovery for multi-tenant servers, elicitation (server→user input), and untrusted-tool-result guidance.

MCP spec 2025-11-25

As of: 2026-01 · Revision: 2025-11-25 (previous: 2025-06-18)

Key changes

  • Authorization server discovery via RFC 9727 (protected resources) replaces ad-hoc .well-known handling — multi-tenant MCP servers (one server, many orgs) are now first-class.
  • Elicitation — servers can request structured input from the user mid-flow, complementing sampling. Servers can ask the human for 2FA codes/confirmations instead of inventing values.
  • Tool result integrity — results may carry authenticity metadata; clients SHOULD treat tool outputs as untrusted content (render, don't execute).
  • Streamable HTTP robustness — resumability via Last-Event-ID, tighter JSON-RPC batch rules, clearer shutdown semantics.
  • Async task primitives in draft for the next revision — long-running tool calls returning 202 + status endpoint.

Why agents care

  • Multi-tenant MCP deployments break against old single-issuer OAuth assumptions — use the new discovery flow.
  • Treat every tool result as untrusted input; your harness policy should make the spec's SHOULD a MUST.
  • Prefer elicitation-capable clients for anything touching money or credentials.