01Fixture, real stdio, and remote HTTP share one governed application client contract. Local stdio and an explicit live-read deployment advertise 42 typed tools; default remote HTTP advertises only the 32 credential-free tools. Both profiles retain 38 resources and two prompts, OAuth mode binds an attributable principal/client/scope to the exact resource, remote HTTP retains no session registry, and no profile exposes writes.
02A blocked, missing, or unentitled provider produces a useful explicit failure rather than a blank surface or fabricated result.
03No server credential, bearer value, precise private fixture, or provider response body appears in client bundles, logs, screenshots, or test artifacts.
04Resources, listeners, sessions, processes, or requests stop cleanly when the owning screen, request, or application ends.
05Tools have least authority
06Gateway/OAuth and provider credentials are independent
07Issuer, resource audience, principal, client, expiry, and profile scope are enforced
08Consent, rate limiting, revocation, TLS, and egress are production-governed
09Writes require separate design/approval
10Results preserve provenance
11Calls are scoped, metered, redacted, and traceable