1. Control can be done via CLIs --> api key based access controls. We have been doing it forever.
2. I think this really only applies to Oauth based MCPs. Many server support api key based auth, stored as files --> security is still flawed imo.
3. This can be done via apis/clis too --> not something unique to MCP iimo
4. Same thing, not unique to MCP --> api servers can also be logged
MCP doesn't inherently make this easier. its still requires engineering maintaincence.