Remote MCP servers use OAuth 2.1. Per-tool scopes; default-deny.
What you're seeing
Hosted MCP servers handling sensitive data require OAuth. Client gets an access token with
scopes; each tool requires specific scopes. Server validates on every call.