The MCP Auth Gap Is Real, and the NSA Just Put It in Writing
Self-hosting a Model Context Protocol server on a public web server exposed a problem the protocol does not solve on its own. A new NSA report describes the same gap in formal language, and here is the architecture I landed on to close it.