53°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Aaron Parecki
    The latest version of the MCP spec is now officially 2025-06-18! Congrats to everyone in the MCP community involved in making this happen!

    Key updates to the authorization section:

    ⚙️ MCP Servers are no longer responsible for issuing access tokens or handling user authentication
    🛡️ A dedicated Authorization Server separate from the MCP Server handles user authentication and issuing access tokens
    🔍 RFC9728 Protected Resource Metadata enables the MCP client to dynamically discover the MCP Server's authorization server
    👉 RFC8707 Resource Indicators are required as a security measure

    Thanks to everyone who contributed to the many discussions to update the authorization part of the spec to be more compatible with existing OAuth systems!

    David Soria Parra, Paul Carleton, Den Delimarsky, Nate Barbettini, William Dawson, Jared Hanson, Karl McGuinness, Darin McAdams, Jean-François LOMBARDO and apologies if I forgot to mention you, those threads were extremely long!

    #modelcontextprotocol #mcp #oauth #ai
    Portland, Oregon, USA • 70°F
    Wed, Jun 18, 2025 7:07pm -07:00 #modelcontextprotocol #mcp #oauth #ai
    1 like 3 replies
    • Laurens
    • Aaron Parecki bsky.app/profile/aaronpk.com
      Thanks to everyone who contributed to the many discussions to update the authorization part of the spec to be more compatible with existing OAuth systems!
      Thu, Jun 19, 2025 2:08am +00:00 (via brid.gy)
    • Aaron Parecki bsky.app/profile/aaronpk.com
      🔍 RFC9728 Protected Resource Metadata enables the MCP client to dynamically discover the MCP Server's authorization server
      👉 RFC8707 Resource Indicators are required as a security measure
      Thu, Jun 19, 2025 2:08am +00:00 (via brid.gy)
    • Aaron Parecki bsky.app/profile/aaronpk.com
      ⚙️ MCP Servers are no longer responsible for issuing access tokens or handling user authentication
      🛡️ A dedicated Authorization Server separate from the MCP Server handles user authentication and issuing access tokens
      Thu, Jun 19, 2025 2:08am +00:00 (via brid.gy)
Posted in /notes using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv