How MCP grew up: from experiment to enterprise trust boundary in two years
ThickAnalyst8814 · reddit · 2026-08-25
The author, who built integrations against this surface throughout the window, traces MCP's evolution from experiment to enterprise trust boundary:
- Nov 2024: Anthropic open-sources MCP (JSON-RPC over stdio), mostly local processes to Claude Desktop.
- Mar 2025: spec adds Streamable HTTP + OAuth 2.1; OpenAI commits same day, turning it into an industry protocol.
- Apr 2025: Invariant Labs publishes the tool poisoning attack, the first serious public exploit.
- Jun 2025: every MCP server formally classified as an OAuth 2.1 resource server (RFC 9728) with a standard trust boundary.
- Nov 2025: anniversary spec adds Client ID Metadata Documents, Enterprise-Managed Authorization, mandatory PKCE.
- Dec 2025: donated to the Linux Foundation's Agentic AI Foundation (OpenAI, Block co-founders; Google/Microsoft/AWS backing).
- Apr 2026: Salesforce Hosted MCP goes GA with per-user OAuth 2.0, scoped grants, auditable revocable read-only agent access.
Key takeaway: two years ago every security review meant re-litigating how to prove a credential only reads, only as this user, only against this resource — now every failure mode has a spec-sanctioned answer. The trust model stopped being reinvented per implementer.
More from coding & agent
- VecturaKit: Swift-based on-device vector database with MLX acceleration — rudrank · 2026-08-25
- Building a Multi-Agent Personal Assistant Workflow with Claude — michael_k18 · 2026-08-25
- Browser Use CLI reportedly boosts Hermes agent performance 10x — intellectronica · 2026-08-25
- session-migrate: move coding agent sessions across Claude Code, Codex in one command — xhluca · 2026-08-25
- SUCCESSOR Ω: Neural-Symbolic System Generates and Evolves Executable World Programs — Ghost_Pilot_MD · 2026-08-25
- AI Fact-Checker Audit: 1 in 18 Citations Were Fabricated — jonathancheckwise · 2026-08-25