All three were fixed in 0.20.1 on npm and on the hosted endpoint. Use ?scopes=read (or read,write) on the hosted endpoint, or repeat the --scope flag on the CLI to combine scopes; list_tools now hides out-of-scope tools and the header consumer_id wins.

Context: GitHub issue on apideck-libraries/mcp 0.19.0: the scopes query param and CLI scope flag were never applied, list_tools did not hide out-of-scope tools, and a consumer_id in the request body overrode the one in the header.