CourseModel Context Protocol · Module 7: Authorization · part 43 of 83
Part 43 · Module 7: Authorization

Topic 4: Scopes and rules

21 min read·22 Sept 2026

C.1 Least-privilege scopes per tool

Least privilege means a token should carry only the permissions the current job needs. If a token that can only read leaks, the damage is limited to reading. For the notes server the mapping is short, and we write it down as a table because it is the contract between the server, the authorization server's scope configuration, and the host:

CapabilityKindScope neededWhere it is enforced
search_notestool, read-onlynotes:readHTTP layer (required_scopes)
notes://index, notes://{note_id}resourcesnotes:readHTTP layer
summarise_topicpromptnotes:readHTTP layer
create_notetool, writes a filenotes:read and notes:writeHTTP layer plus the check inside the tool
A future delete_note (not built in this course)tool, destructivea separate notes:deleteinside the tool

Two design notes. First, scope names describe what the holder can do to which data, not which tool they may call: if we later add append_to_note, it should reuse notes:write rather than invent tool:append_to_note. Second, the spec says servers MUST respect scope hierarchies where a broader scope implies narrower ones. We have no hierarchy yet; if you add something like notes:admin, make the check in create_note accept it too.

The rest of this course is yours to keep

This course is bought on its own, once, and stays readable afterwards, including the parts added to it later.