Which authenticated machine identity is asking?
OPEN AUTHORITY PROTOCOL
MCP2 asks whether the machine may act now.
MCP2 — Machine Authority & Evidence Profile defines the authority decision between a machine request and a protected side effect. It provides normative protocol semantics for exact actor, action, target, purpose, policy, time, and current authority state.
MCP2 / PROTOCOL / AUTHORITY-EVALUATIONFROZEN / QUALIFIED · SEPTEMBER 23, 2026
Candidate v0.8.0
The current product pin is 0.8.0-candidate, profile MCP2-CORE, at public implementation commit dc890456594e7d8f8eda92c4fa590800a8636942. Candidate status is not external standards certification.
NAMING BOUNDARY
Machine Authority & Evidence Profile.
MCP2 has normative protocol semantics, but it is not “MCP version 2.” It does not replace the Model Context Protocol and is not MCP's successor. MCP supplies interoperability; MCP2 answers the separate question of whether a machine has valid authority for a specific consequential request and how that decision can later be reconstructed.
AUTHORITY VECTOR
Authority is evaluated as a bound set—not a reusable yes.
An ALLOW for one combination cannot be generalized into authority for a neighboring action, target, purpose, tenant, or time.
What exact capability would be exercised?
Which exact protected resource would be affected?
Why was this authority granted?
Which immutable constraints govern the decision?
Is the authority current at the execution boundary?
Has the grant expired, been revoked, or been superseded?
DECISION LOGIC
Current authority must survive every binding.
The fence is not checking whether a grant once existed. It is checking whether the grant is current, exact, unrevoked, unexpired, policy-matching, tenant-bound, and replay-safe at the moment execution is requested.
identity authenticatedPASStenant and target boundPASSaction and purpose exactPASSpolicy digest currentPASStime window openPASSgrant unrevokedPASSnonce unusedPASSdecisionALLOWPROTOCOL BOUNDARIES
What the protocol refuses to collapse.
Possession ≠ authority. A credential proves capability or identity; it does not prove permission for the requested consequence.
Proposal ≠ ratification. A machine can form and submit a request. It cannot transform that request into human authorization.
Past validity ≠ current authority. Authority that was once valid may now be expired, revoked, superseded, or rooted in compromised trust.
Canonical history ≠ independently proven history. A record can be internally consistent and still require independent witness evidence for stronger provenance claims.
ALLOW ≠ execution. The decision receipt records authority evaluation. Completion evidence records what the target later reports happened.
PROTOCOL BOUNDARY
Connection, authority, and execution remain separate.
MCP2 is not MCP v2. The public project is MCP2 — Machine Authority & Evidence Profile.
MCP2 does not replace MCP. Tool connection and machine authority answer different questions.
MCP2 does not execute customer actions. The target performs its own local side effect after ALLOW.
MCP2 does not turn credentials into authority. Possession remains only one input to identity or capability.
UPSTREAM MCP BOUNDARY
Interoperability context can constrain authority. It cannot create it.
MCP connection/authentication ≠ MCP2 authority. Identity and transport authorization remain inputs or evidence.
MCP Task state ≠ MCP2 authority. Queued, running, or complete workflow state never refreshes or widens a grant.
MCP Skill content ≠ MCP2 authority. Skill instructions may be versioned evidence, not human ratification.
PayMAXAIOS clearance ≠ MCP2 authority. Paid actions remain independently dual-gated.
OPERATE THE BOUNDARY
MCP2 defines the decision. MCPaios operates the lifecycle.
See how proposals become bounded authority, how authority reaches the fence, and how outcomes become reconstructible records.