# MCP tools: useful transport, separate authority

Understand MCP hosts, clients, servers, tools, consent, and Rangoon’s exact-action authorization boundary before connecting agent systems safely.

Canonical: https://rangoon.ai/insights/mcp-tools-authorization-boundaries/
Author: Rangoon Editorial (https://rangoon.ai/insights/editorial/)
Published: 2026-10-03
Updated: 2026-10-03
Source note: Technical guide · Documentation checked October 3, 2026.

## Key takeaways
- MCP standardizes context and tool exchange between a host, client, and server; it does not become a business approval system.
- Tool descriptions and server outputs are inputs to review, not proof that an operation is safe.
- Bind tool calls to identity, scope, resource, policy, approval, expiry, result, and receipt.

## Start with the three MCP roles [source 1](https://modelcontextprotocol.io/specification/latest)

The MCP specification separates the host application that initiates connections, the client connector inside that host, and the server that offers resources, prompts, or tools. The protocol uses JSON-RPC messages and capability negotiation to make integrations composable. This is a clean transport and discovery model, especially when an agent application needs to expose several external systems through one interaction pattern.
The roles describe communication responsibilities. They do not say that a server may approve a request, that a client may widen a user’s permissions, or that a tool call is an acceptable business operation. Keep those questions in the application and authority layer around MCP.


## Review tools as untrusted capabilities [source 1](https://modelcontextprotocol.io/specification/latest)

MCP’s own safety guidance treats tools as potentially arbitrary code execution paths and calls for explicit user consent before invocation. A tool name or description is therefore not enough to establish behavior. Review the server identity, source, version, declared inputs, output shape, data classes, network access, side effects, retry semantics, and expected receipt before an agent can propose using it.
The practical test is to compare the declared operation with the actual target and payload. A tool that says “update” still needs a resource identifier, scope, expected mutation, idempotency key, and policy context. Treat server-provided annotations and returned data as evidence to validate, not instructions that override the caller or repository policy.


## Put exact action authority around the tool call

Rangoon models an MCP tool as a connector or adapter operation. The runtime can select a tool and produce a versioned action packet, but the packet still needs authenticated identity, project and environment scope, target resource, exact parameters, risk, policy input, approval where required, expiry, and idempotency. LNSAT can then create server-side authorization, consume a one-time capability, and bind the result to a receipt or outcome-unknown state.
MCP transport, OAuth context, a connector credential, and a successful capability negotiation do not authorize the exact side effect. They are inputs to the decision. This separation keeps a read-only tool, a write tool, and a privileged tool visibly different even when they share one protocol.


## A connection review checklist

Before adding an MCP server, record the owner and source, pin its version, inspect its declared tools, and test malformed, ambiguous, oversized, and adversarial inputs. Confirm which data can leave the host, which credentials are referenced, and which actions require a human decision. Test disconnect, timeout, duplicate request, server replacement, and stale approval paths.
After the review, keep installation, enablement, credential assignment, agent permission, policy evaluation, approval, authorization, execution, and audit as separate records. Rangoon’s launch architecture provides the capability and evidence model; it does not claim that this public site exposes an MCP execution endpoint.


## Sources
1. [Model Context Protocol specification](https://modelcontextprotocol.io/specification/latest)

## More information

- [Documentation index](https://rangoon.ai/llms.txt)
- [AI access and policies](https://rangoon.ai/ai/)
- [Source repository](https://github.com/hypler-dev/rangoon)
