# दूरस्थ Servers और Authorisation — MCP और Agent-to-Agent Protocols

Source: https://www.geekswithgeeks.com/hi/mcp-a2a/c-remote-auth

> दूरस्थ MCP servers को उचित OAuth-शैली authorisation से सुरक्षित करें।

## दूरस्थ का अर्थ असली authentication

स्थानीय stdio server user के रूप में चलता है, पर **दूरस्थ** server network सेवा है जिसके पास दूसरों का डेटा हो सकता है, इसलिए उसे उचित **authentication और authorisation** चाहिए। MCP विनिर्देश **OAuth 2.1** पर बनता है: server संरक्षित resource की तरह काम करता है, client user की सहमति के बाद authorisation server से **access token** पाता है, और हर अनुरोध के साथ `Bearer` token के रूप में भेजता है; tokens **अल्पकालिक**, ज़रूरत भर तक **सीमित (scoped)** और **इच्छित server से बँधे** (audience) होते हैं। Client का token आगे अन्य downstream APIs को **न** दें ("confused deputy" समस्या); अलग credentials बदलें या जारी करें। हमेशा HTTPS उपयोग करें, स्थानीय HTTP servers के लिए `Origin` header validate करें, और rate-limit लगाएँ। Authorisation के ब्योरे विनिर्देश संस्करणों में विकसित हुए हैं, इसलिए मौजूदा विनिर्देश अनुसरण करें।

## शब्दों में authorisation प्रवाह

सरलीकृत क्रम; ब्योरे विनिर्देश संस्करण के अनुसार बदलते हैं।

```text
1. client calls the MCP server without a token  -> 401 + pointer to its authorisation server
2. client discovers the authorisation server and registers / identifies itself
3. user is sent to sign in and approve the requested scopes (consent)
4. client receives a short-lived access token (audience = this MCP server)
5. client sends   Authorization: Bearer <token>   on every request
6. server validates signature, expiry, audience, scopes -> else 401/403
7. server must NOT forward this token to other APIs; it uses its own credentials
```

## न्यूनतम scope, सबसे छोटा जीवनकाल

जो चले उतने ही संकरे scopes माँगें, और refresh के साथ छोटे token जीवनकाल रखें, ताकि लीक हुआ token सीमित नुक़सान करे।

**Quiz:** MCP server को client का token दूसरी APIs को क्यों नहीं भेजना चाहिए?

- [x] यह confused-deputy जोखिम है और audience binding तोड़ता है
- [ ] Tokens बहुत लंबे हैं
- [ ] APIs tokens नहीं पढ़ सकतीं
- [ ] यह अनुरोध तेज़ करता है

*Answer:* यह confused-deputy जोखिम है और audience binding तोड़ता है. Tokens एक audience के लिए हैं; उन्हें आगे भेजना सेवाओं को ऐसे अधिकार से कार्य करने देता है जो उन्हें दिए नहीं गए।
