I was wondering what kind of client name they were talking about.
It's really silly that this was the only means of blocking access. I expected them to have, I don't know, some sort of cryptographic signature or something.
An additional JWT with a long expiry time would even work here, anything.
Ironically, it's exactly the kind of "security" I imagine current Claude models would work around as a matter of course, with barely a note left for the user to know the agent hit a speed bump when operating the MCP.