How to study for the MCPA security and governance domain
Blog post from WorkOS
The Agentic AI Foundation and Linux Foundation Education introduced the vendor-neutral Model Context Protocol Associate certification on September 14, 2026, based on the MCP 2026-07-28 specification, with security and governance comprising 24% of its 90-minute online multiple-choice exam. The security material emphasizes trust boundaries, audience-bound access tokens that must not be forwarded to upstream APIs, per-tool authorization checks, explicit delegation, least-privilege permissions, and the distinction between requesting broader scopes and re-authenticating users. It also covers human approval, time-limited session authorization, the fact that tool annotations are advisory rather than enforceable controls, and transport-specific requirements such as using environment credentials rather than OAuth for STDIO implementations. Because the revised protocol is stateless, identity and authorization details must accompany each remote request, while meaningful auditability requires identifying the agent, delegating user, authorized scope, and approval context rather than merely recording actions. Candidates are encouraged to understand OAuth 2.1, PKCE, protected resource metadata, resource indicators, and the shift from Dynamic Client Registration toward Client ID Metadata Documents; the $250 certification is valid for two years and includes 12 months of eligibility and one retake.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 15 | 2,241 | 148 | 72 | -74% |
| AI Agents | 3 | 931 | 231 | 103 | -84% |
| Observability | 1 | 472 | 102 | 54 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.