We deleted our MCP server's permission model—reuse your REST authz instead

Wide-Excitement-1315 · reddit · 2026-09-29

After a year running an MCP server against a multi-tenant production app, the author's team found their REST and MCP authorization policies had drifted, and fixed it by deleting MCP's separate policy layer. Key lessons: MCP tools must run the same capability and record-scope checks as REST endpoints; secure what agents hold, not what they're asked (grant only capabilities you hold yourself); check who already holds a tool before locking it down; and beware granted tools failing silently when names miss the registry—a bug that shipped twice, now caught at build time.

Original post →

More from coding & agent

coding & agent channel →