A draft MCP proposal wants servers to show a signed pass before any tool runs.
By Lior AharonovFounder, 7IT Solutions ·
SEP-2809 is a draft that still has no sponsor; it had new review activity on 30 September 2026. A server would publish an Ed25519-signed document at /.well-known/mcp-attestation, and the host would check it against a trust root it pinned before allowing tools. Every admission and denial would go into a hash-chained, append-only audit log.
Today a client knows a server by its address and a login. Under this draft it would also check a signed document before your first tool call runs.
Nothing to do yet; watch for SEP-2809 to find a sponsor.
Every protocol ends up rebuilding the passport office. The only open question is who holds the stamp.
Lior Aharonov · my takeSources
Researched with AI tools; every fact is checked against the linked sources.