Hiding an MCP tool isn't security: authorization must be enforced server-side

Stock-Pumpkin-8859 · reddit · 2026-10-07

A developer lays out an MCP security point: removing a tool from the agent's tool list only controls discovery, not authorization. Real permission checks belong on the MCP server — verifying who is making the request, what they can access, which records they own, and whether the action needs approval. Tool descriptions guide the model but shouldn't be treated as authorization rules.

Write actions are the critical case: even if a dangerous tool is hidden, the server should still reject calls arriving without proper permissions. The author asks how teams handle this without duplicating the permission system: enforce inside every tool, front the server with an authorization layer, or both — and how to handle per-user/per-tenant permissions.

Original post →

More from coding & agent

coding & agent channel →