7MAPS

7Maps · News

A draft MCP proposal wants servers to show a signed pass before any tool runs.

By Lior AharonovFounder, 7IT Solutions ·

What happened

SEP-2809 is a draft that still has no sponsor; it had new review activity on 30 September 2026. A server would publish an Ed25519-signed document at /.well-known/mcp-attestation, and the host would check it against a trust root it pinned before allowing tools. Every admission and denial would go into a hash-chained, append-only audit log.

Why it matters

Today a client knows a server by its address and a login. Under this draft it would also check a signed document before your first tool call runs.

What to do

Nothing to do yet; watch for SEP-2809 to find a sponsor.

Every protocol ends up rebuilding the passport office. The only open question is who holds the stamp.

Lior Aharonov · my take

Sources

specificationtrust

Researched with AI tools; every fact is checked against the linked sources.

All 7Maps news · Atom feed

A correction: lior@7it.co.il. 7Maps by 7IT.