Our deployment steps for the central mcp registry have is cloning a 3rd party repo and building a go tool to publish server.json files. I suspect the API call is just signed with our keyvault based private key or we're using the key to mint a bearer token.
Replacing that process with powershell scripts in our repo would reduce our security exposure at the cost of owning maintenance for our own publishing script.