What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Secure an MCP server as both an ordinary API and an LLM-facing capability. Authenticate every request, verify that the token was issued for your server, keep upstream credentials separate, minimize each tool’s permissions, validate model-influenced data, isolate local processes, and monitor tool activity. The Model Context Protocol’s authorization requirements are mandatory; OWASP and Microsoft guidance adds recommended defenses for prompt injection, tool poisoning, supply-chain risk, and operational monitoring.
What an MCP server must defend
A typical deployment has a host application, an MCP client, one or more MCP servers, tools, and external APIs. Tool descriptions, parameter schemas, and returned content are placed in a model’s context. That creates security paths that a conventional JSON API does not have: an attacker can hide instructions in a tool description or in fetched content, and a model can select a powerful tool with attacker-influenced arguments.
- Confused deputy: a server uses broad privileges without checking whether the requesting user is allowed to perform the action.
- Tool poisoning and rug pulls: a malicious description or schema changes after a user has approved a tool.
- Cross-server shadowing: one server presents a tool name or behavior that causes the client to invoke the wrong implementation.
- Unsafe execution: raw shell commands, unrestricted file paths, arbitrary URL fetching, or an escape from a local sandbox.
- Credential and data leakage: bearer tokens, personal data, or secrets appear in logs, model context, or upstream requests.
Model Context Protocol security best practices, the authorization security considerations, and OWASP’s MCP cheat sheet describe these risks in detail: MCP security best practices, MCP authorization security considerations, and the OWASP MCP Security Cheat Sheet.
Remote authorization: requirements you cannot skip
Validate the token for this resource
The MCP authorization security document dated 2026-07-28 requires clients to include the resource parameter in authorization and token requests. A server must reject a token that was not issued for that MCP server, validate it before processing the request, and check its issuer, audience or resource, expiry, and applicable scopes. A validly signed token is not automatically valid for your service.
#1 Best Overall
- Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
- Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
- High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
- Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
- What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform
Authorize every request, including requests that only enumerate tools or fetch metadata. Transport encryption protects the connection; it does not establish that the caller is entitled to invoke a particular tool.
Use the required OAuth protections
- Clients must use PKCE and use the S256 challenge method when capable.
- Clients must verify that the authorization server supports PKCE before proceeding.
- Authorization endpoints must use HTTPS. Redirect URIs must be localhost or HTTPS.
- Store access and refresh tokens in protected storage, never plaintext configuration, source control, or logs.
- Prefer short-lived access tokens to reduce the damage from a leak; rotate or revoke longer-lived credentials.
Keep the inbound token away from upstream APIs
An MCP server must not forward the client’s bearer token to an upstream service. Exchange or obtain a distinct credential from the upstream authorization server, scoped to that API. This separation prevents an upstream compromise or misconfiguration from turning an MCP token into a general-purpose credential.
Implement authorization before tool dispatch
The following Python example shows the order of checks. It is deliberately explicit: your identity provider’s issuer, resource identifier, key set, and scope names belong in protected configuration.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
import os
import jwt
from jwt import PyJWKClient
ISSUER = os.environ["MCP_ISSUER"]
RESOURCE = os.environ["MCP_RESOURCE"]
JWKS_URL = os.environ["MCP_JWKS_URL"]
keys = PyJWKClient(JWKS_URL)
def authorize_request(authorization_header, required_scope):
if not authorization_header or not authorization_header.startswith("Bearer "):
raise PermissionError("missing bearer token")
token = authorization_header[7:].strip()
try:
signing_key = keys.get_signing_key_from_jwt(token).key
claims = jwt.decode(
token,
signing_key,
algorithms=["RS256"],
issuer=ISSUER,
audience=RESOURCE,
options={"require": ["exp", "iss"]},
)
except jwt.PyJWTError as exc:
raise PermissionError("invalid token") from exc
scopes = set(claims.get("scope", "").split())
if required_scope not in scopes:
raise PermissionError("insufficient scope")
return claims
In production, bind authorization to the specific tool and operation, not only to the server. Do not log the token, decoded secrets, or full personal claims. If your provider uses a resource claim rather than an audience claim, enforce that exact documented claim instead of accepting either value silently.
Design tools with least privilege and strict contracts
Make permissions narrow and auditable
Give each server only the credentials and network destinations it needs. Give each tool only the scopes required for its operation. Separate read, write, delete, payment, and data-sharing actions so a read-only workflow cannot accidentally call a destructive capability. Review tool descriptions, parameter names, and return schemas as code; an instruction hidden in metadata is still untrusted input.
Validate arguments and results
- Use strict JSON Schema with required fields, bounded strings and numbers, enumerated values, and maximum sizes.
- Validate model-generated arguments again on the server. Never rely on the model or client to enforce a schema.
- Treat tool output as data, not instructions. Sanitize or mark untrusted text before placing it back into model context.
- Require explicit user confirmation for destructive, financial, credential-changing, or external data-sharing actions.
- For URL-fetching tools, use an allowlist of schemes, hosts, ports, and redirect destinations. Block private, loopback, link-local, and cloud-metadata addresses to reduce SSRF risk.
- Do not execute raw shell commands supplied by a model. Map an operation to a fixed command and fixed argument set, or remove command execution entirely.
- Resolve file paths against an approved directory, reject traversal and symlinks that escape it, and enforce file-size and time limits.
Example: allowlisted URL fetching in Node.js
const allowedHosts = new Set(["docs.example.com", "api.example.com"]);
export function validateFetchTarget(raw) {
const u = new URL(raw);
if (u.protocol !== "https:") throw new Error("HTTPS required");
if (!allowedHosts.has(u.hostname)) throw new Error("host not allowed");
if (u.username || u.password) throw new Error("credentials in URL rejected");
return u;
}
export async function fetchApproved(raw) {
const target = validateFetchTarget(raw);
const response = await fetch(target, { redirect: "error", signal: AbortSignal.timeout(10000) });
if (!response.ok) throw new Error(`upstream status ${response.status}`);
return response.text();
}
Defend against prompt injection and changing tools
Microsoft’s guidance on indirect prompt injection in MCP explains that external content can contain instructions and that tool poisoning can be embedded in MCP tool descriptions. Treat prompt shields and content filters as additional controls, not as proof that injection is solved.
Rank #3
- [Large Capacity & Apron-Friendly] Measuring an oversized 4.7 x 9 inches, this larger server book provides extra room for taller receipts, guest checks, and menus while still fitting perfectly into standard restaurant aprons. (Note: apron and guest check pads are not included.)
- [Secure Magnetic & Zipper Pockets] Features a powerful magnetic closure pocket to securely hold large amounts of cash flat, alongside a heavy-duty zippered pocket to keep coins from falling out. Perfect for keeping your bills, receipts, change, and credit cards safely locked away during a hectic shift.
- [Classic Black & White Polka Dot Design] Crafted from high-quality, soft PU faux leather, this server book features a timeless black background accented by retro-chic white polka dots. It brings a touch of modern fashion to your workday, brightening your uniform while matching any restaurant dress code.
- [Professional Craftsmanship & Durability] Built to withstand the grueling, fast-paced demands of the food service industry. Engineered with reinforced seams and meticulous stitching that won't fray, this lightweight organizer offers a polished, high-end look that stands up to daily wear and tear.
- [The Ultimate Shift Organizer] The perfect shift companion for busy waitstaff, servers, and bartenders. Whether you are holding cash, writing down orders, or tracking daily food and wine specials, this stylish book keeps you organized, fast, and efficient under pressure.
- Record an approved inventory of server identities, tool names, descriptions, schemas, and required scopes.
- Diff newly discovered definitions against that inventory. Require review when a description, parameter, return schema, endpoint, or permission changes.
- Pin server versions and dependency versions where practical; verify package integrity and inspect source before installation.
- Display the exact consequential action and relevant arguments to the user before approval. Do not show only a friendly summary generated by the model.
- Keep untrusted fetched text in a clearly separated data field and prevent it from silently changing the system’s instructions or authorization state.
Secure local servers and state handles
Local stdio processes
A local server can read files, use the network, and execute code with the host user’s privileges. Run it under a dedicated account or sandbox, grant only the directories and outbound destinations it needs, and deny access to credential stores and unrelated projects. Review the source, lock dependencies, and check package names for typosquatting before installation. Make the user review and explicitly approve the exact command that starts a local server.
Local HTTP servers
Bind to a restricted interface, limit who can reach the port, and require authorization rather than assuming that “localhost” is a trust boundary. Disable unnecessary methods and enforce request-size, rate, and timeout limits.
State handles are not authentication
If a server returns a handle for later use, possession of that handle must not be treated as proof of identity. Bind the handle to the verified user and intended server, generate it with an unpredictable random source, and expire or revoke it. Reject a handle presented by a different user even when its value is otherwise valid.
Rank #4
- 5 Pockets & 1 Pen Hook: Keep essentials neatly organized with 5 pockets for cash, cards, receipts, and guest checks, plus a pen holder for easy access.
- Perfect Size for Aprons: Compact 5”x7” size fits comfortably in aprons without poking or bulging. Expandable design ensures easy handling, helping you stay professional and efficient.
- Durable & Easy to Clean: Made from premium, cruelty-free PU leather that’s water-resistant and scratch-proof. Easy to clean, ensuring it stays looking great through busy shifts.
- Stay Organized on the Go: Designed to keep everything securely in place, this server book helps you stay organized even during the busiest shifts, so you can focus on providing great service.
- High Quality at an Affordable Price: A well-crafted server organizer that offers premium quality at a reasonable price, trusted by waitstaff for everyday use.
Log, monitor, and review the supply chain
Centralize invocation logs with server and tool identifiers, authenticated user or service identity, timestamp, outcome, latency, and a safe summary of arguments. Redact access tokens, passwords, personal data, and sensitive tool output before storage. Add alerts for unusual tool sequences, repeated authorization failures, new outbound destinations, large data transfers, permission changes, and definition changes. Keep enough immutable history for incident investigation while applying retention and access controls appropriate to the data.
Isolate MCP servers from one another where possible and monitor cross-server data flows. A server that can read a sensitive system should not automatically be able to send that data to every other server or external API.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Choose an architecture deliberately
| Decision | Local stdio |
Remote HTTP |
|---|---|---|
| Who can reach it | Usually one host process, but with the host user’s local privileges | Any permitted network caller; exposure and authentication boundaries must be explicit |
| Primary controls | Process sandbox, filesystem and network restrictions, reviewed startup command | HTTPS, token validation on every request, rate limits, authorization and network policy |
| Credential storage | Protected local OS storage or injected secret with minimal scope | Dedicated secret store or protected runtime injection; never client-token passthrough |
| Operational concern | Dependency and host compromise | Internet exposure, replay, logging, and tenant isolation |
| Authorization model | Per-user delegated access | Service credential |
|---|---|---|
| User-level fidelity | Best when every action must reflect the requesting user’s rights | All calls share the service identity unless the server adds its own policy layer |
| Scope minimization | Short-lived, user-specific scopes can be narrow | Requires a tightly limited service account and careful tool partitioning |
| Auditability | Direct user attribution in the upstream system | Server logs must preserve the initiating user separately |
| Lifecycle | OAuth consent, refresh, revocation, and expiry must be handled | Rotation and secret distribution are simpler but compromise affects every caller |
A practical implementation sequence
- Draw the host, client, server, tool, identity provider, and upstream API boundaries.
- Assign one resource identifier, issuer, and minimum scope set to each remote server.
- Implement token validation before request parsing or tool dispatch; reject wrong issuer, resource, expiry, or scope.
- Issue or obtain a separate upstream token and keep it out of MCP responses and logs.
- Write strict schemas and validators for every argument and return value; add confirmations for high-impact operations.
- Lock down URL, file, shell, network, and time budgets. Add tests for traversal, SSRF, oversized inputs, and malformed JSON.
- Snapshot tool definitions, review changes, pin dependencies, and verify package provenance.
- Deploy least-privilege sandboxes, centralized redacted logs, anomaly alerts, and an incident-revocation procedure.
- Run adversarial tests with poisoned descriptions, malicious fetched text, replayed handles, expired tokens, and cross-tenant requests.
Troubleshooting common failures
| Symptom | Likely cause | Fix |
|---|---|---|
| Every request returns 401 | Issuer, audience/resource, signing key, or clock is wrong | Inspect non-secret claims, synchronize clocks, refresh JWKS, and verify the exact resource value used in authorization and token requests. |
| Token works at the identity provider but not at the MCP server | The token was minted for another API | Request a token for this server’s resource; never accept a token merely because its signature is valid. |
| Upstream API rejects calls | The MCP bearer token was forwarded or lacks upstream scopes | Obtain a separate upstream credential with the required scope and send only that credential upstream. |
| A tool suddenly requests new permissions | Definition change or rug pull | Compare with the approved snapshot, block invocation, review the source and dependency change, then re-approve deliberately. |
| URL tool reaches internal services | Open fetching, redirects, DNS rebinding, or IP validation gap | Use an HTTPS host allowlist, resolve and validate destination IPs, disable redirects, and block private and metadata ranges. |
| A local tool reads unrelated files | Process runs with broad host permissions or path traversal | Sandbox the process, mount only an approved directory, canonicalize paths, reject traversal, and deny symlink escapes. |
| Logs contain credentials | Headers or tool arguments logged wholesale | Redact before serialization, test redaction rules, restrict log access, and rotate any exposed secret. |
Or skip the browser setup
If your MCP integration needs website screenshots, ScreenshotNeo provides a website screenshot API and MCP server. It accepts consent banners before capture and removes more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP tools—take_screenshot, get_page_info, and capture_pdf—can be used by Claude, Cursor, or another MCP client. Treat it like any external tool: use a dedicated API key, least-privilege access, HTTPS, redacted logs, and explicit approval for captures that may contain sensitive data.
One request is enough:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
See the ScreenshotNeo documentation for options. The same call in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
And in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`ScreenshotNeo returned ${res.status}`);
The free plan includes 1,000 screenshots each month with no card; paid plans start at $5 for 3,000 shots, and every feature is included on every plan. Create a free ScreenshotNeo account.
Final security standard
An MCP server is ready for production only when identity, authorization, tool contracts, execution boundaries, and monitoring are enforced together. Re-test those controls whenever a tool definition, dependency, credential, model-facing prompt, or upstream integration changes.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

