Shipping an OAuth-protected remote MCP server: the spec and 3 security bugs (opens in new tab)
We made SkillDB a one-paste Claude Desktop connector — which meant becoming an OAuth 2.1 server. Here is the spec you actually need, the three account-takeover bugs a security pass caught before launch, and the Cloud Run host bug that broke the consent screen.
Read the original article