Security considerations section can be improved

Author: loganadenCreated Sep 14, 2026Updated Sep 14, 2026
Labelsbug

What's broken?

The spec doesn't cover a case it clearly should

Where in the spec or docs?

https://github.com/modelcontextprotocol/modelcontextprotocol/commit/5948f5c10ef5c42089122320d58d7369bb465f3d

What should happen?

All endpoints, including token bearing endpoints should use HTTPS.

Please see this PR: https://github.com/modelcontextprotocol/modelcontextprotocol/commit/5948f5c10ef5c42089122320d58d7369bb465f3d

What actually happens?

All endpoints, including token bearing endpoints should use HTTPS.

Anything else?

No response

Source: modelcontextprotocol/modelcontextprotocol