A stdio MCP server gets four things free from having one caller that shares its context. Once the transport is remote, each becomes a decision.
AUDIENCE. A correctly signed, unexpired token minted by the trusted issuer for a different resource reaches nothing. So does one made out to this resource and another, which PyJWT would accept. The SDK carries an RFC 8707 resource field and never compares it to anything, so the check is written here or it does not exist.
REACH. A tool outside a caller's granted scope is absent from its listing, and asking for it anyway returns bytes identical to asking for a name that never existed.
BUDGET. The vendor publishes no rate limit, no rate-limit header, and does not list 429 among its status codes, so a reactive limiter has nothing to react to. Each caller has a reserve nobody else can spend: under one shared bucket the quiet caller gets 0 of 60, under this one it gets exactly its 15.
COVERAGE. Twelve calendar days requested across Easter return eight observations, and the response is complete, because four of the absences are closures. Every tool that returns observations carries a certificate saying what did not arrive and why.
All four are proved twice: 132 Python tests, and 16 checks driven from TypeScript on the official MCP SDK against the running server, sharing no code with it.
Source: ECB statistics.