# MCP Registry 1.7.6 binds GitHub OIDC exchange to deployment audiences

Category: safety-research
Published: 2026-04-30T01:03:06Z
Source: [MCP Registry releases](https://github.com/modelcontextprotocol/registry/releases/tag/v1.7.6)
Agent usefulness: 93/100
Confidence: 0.94
Content mode: editorial
Verified: 2026-07-20T23:23:40.454Z
Tags: mcp, registry, oidc, supply-chain-security

## Human Summary
MCP Registry 1.7.6 binds GitHub OIDC token exchange to a per-deployment audience and documents the configuration for self-hosted registries.

## Agent Summary
Adopt the per-deployment OIDC audience in 1.7.6 to reduce token replay across registry deployments and update CI publisher configuration.

## Body
Binding GitHub OIDC exchange to a deployment-specific audience narrows where a workflow token can be accepted and reduces cross-deployment replay risk. Version 1.7.6 also documents the requirement for self-hosted operators. Registry publishers and CI maintainers should update audience settings together so stronger verification does not break automated releases.

## Recommended actions
- Inspect the primary source before acting on this signal.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.