Security Considerations
Version: mcp_server 2.0.0-beta5, mcp_server_tool_bridge 1.0.0-beta3, mcp_server_oauth 1.0.0-alpha1. All pre-release; none covered by security advisories.
When to Use
Run this checklist before exposing a site over MCP beyond local development. An MCP client can do anything its tools allow, as the acting Drupal user. Each item links to the page that owns the rule.
Decision
| Risk | Rule | Owning page |
|---|---|---|
| Overprivileged acting user | A dedicated, minimal account per agent; never an admin account | Authentication and the Acting User |
| Endpoint reachable by anyone | access mcp server on a dedicated role only; never anonymous |
Authentication and the Acting User |
| Remote client on cookie auth | Use OAuth for remote clients | OAuth Setup |
| Native tool open to all | Override checkAccess() |
Native Tool Plugins |
| Too many tools exposed | Expose only the tools agents need; bridged tools are listed to every caller | Tool API Bridge |
| Destructive actions | Hints are advisory; keep delete tools away from unattended agents | Native Tool Plugins, Tool API Bridge |
| Per-user resource content | Set max-age 0 | Resources and Resource Templates |
| Prompt text | No secrets; prompts have no access check | Prompts |
| Pre-release software | Pin versions; re-check after each upgrade | What MCP Server Is |
Production checklist
- [ ] HTTPS enforced for
/mcpand/oauth/* - [ ]
access mcp servernot granted to anonymous - [ ] OAuth used for every remote client; consumers use PKCE
- [ ] Each agent has a dedicated, non-admin Drupal user
- [ ] Every native tool overrides
defaultConfiguration()andcheckAccess() - [ ] Only needed bridged tools are enabled
- [ ] Destructive tools reviewed and limited
- [ ] Per-user resource content uses max-age 0
- [ ] Prompts hold no secrets
- [ ] Dynamic client registration settings and registered consumers reviewed
- [ ] Versions pinned in
composer.json
Common Mistakes
- Treating
access mcp serveras low-stakes. It isrestrict access: truefor a reason. - Applying the AI module's consuming-side warning (AI module security, AI agents) and stopping there. Serving needs its own review.
- Assuming a read-only agent because the client is "just Claude". The Drupal account decides what it can do.
See Also
- Troubleshooting
- OWASP API Security Top 10: https://owasp.org/API-Security/
- MCP security best practices: https://modelcontextprotocol.io/docs/2026-07-28/tutorials/security/security_best_practices