TL;DR: MCP security now depends on governing the full trust chain, not just authentication, as Apono argues that server-side authorization, task-scoped access, human approval, and lifecycle token controls are required while Anthropic reported more than 10,000 active public MCP servers and 97M+ SDK downloads by December 2025. The practical break point is the assumption that a model can safely choose and execute privileged actions without runtime identity controls.
Editorial analysis by NHI Mgmt Group, based on content published by Apono: “10 MCP Security Best Practices”.
By the numbers:
- Anthropic also reported 97M+ monthly downloads of its Python and TypeScript MCP SDKs by December 2025.
Key questions
Q: What breaks when MCP servers do not require authentication?
A: When MCP servers do not require authentication, the access boundary disappears.
Q: Why do task-scoped privileges matter for MCP-connected agents?
A: Task-scoped privileges matter because MCP agents often need access only for a single operation, not a persistent entitlement.
Q: What are the signs that MCP governance is failing?
A: Common signs include agents reaching systems outside their intended workflow, incomplete audit trails for tool use, and data retrieval that cannot be tied back to a clear business purpose.
Practitioner guidance
- Map the full MCP trust chain Inventory every approved client, server, tool, owner, backend identity, and downstream resource, including locally installed components that developers add outside central procurement.
- Move privileged access to runtime Replace standing permissions with task-scoped, short-lived access so MCP-connected agents receive only the privileges required for the current action.
- Enforce server-side authorization checks Validate the requesting identity, target resource, requested operation, and context at the point of execution rather than relying on authentication or client instructions.
Bottom line: MCP security expands identity governance from login events to the full chain of tools, servers, credentials, and downstream systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Runtime governance is now the real control plane for MCP. Authentication tells you who connected, but it does not control what a connected agent can do next. Once a model can invoke tools that reach data, infrastructure, or administrative APIs, the security decision moves to execution time and must be re-evaluated on every action.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: Should organisations require human approval for all MCP actions?
A: No. Human approval is most valuable for high-risk operations such as destructive changes, large exports, and billing or access modifications. Low-risk read-only tasks can remain automated if the request is tightly scoped and continuously validated. The key is to separate reversible machine tasks from irreversible actions that need accountability.
👉 Read our full editorial: MCP security best practices shift control to runtime governance