Ten thousand authorization servers
You ship an MCP client used by 10,000 companies, each with its own identity provider.
With Dynamic Client Registration, that's 10,000 registrations to create, store per issuer, rotate and clean up. With a Client ID Metadata Document, it's one URL you host: https://yourapp.com/oauth/client.json. Every authorization server fetches it, and you update your redirect URIs in one place.
The attack this closes: a user connects your client to a legitimate server and to a malicious one. The malicious authorization server tries to make your client send it a code meant for the legitimate one, a mix-up attack. Your client compares iss with the issuer it started with, sees a mismatch, and refuses to redeem the code.