78°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • OAuth for the Model Context Protocol

    Jun
    16
    June 16, 2026
    11:30am - 12:30pm (-0700)
    Mandalay Bay
    3950 S Las Vegas Blvd, Las Vegas, Nevada, US
    Identiverse 2026
    The Model Context Protocol (MCP) enables AI agents to connect to diverse data sources, but securing these connections requires rethinking traditional OAuth assumptions. In an open ecosystem where users connect their agents to thousands of arbitrary servers, manual client registration is impractical, and Dynamic Client Registration introduces unacceptable complexity and risk.

    This masterclass from the co-author of OAuth 2.1 and key contributor to the MCP Authorization specification offers a deep architectural dive into the November 2025 MCP spec update. We will dissect the architectural concepts required to secure MCP servers and clients. We'll focus on the key differences and challenges MCP brings to the table when leveraging OAuth specifications, discussing OAuth 2.1, Client ID Metadata Documents, Protected Resource Metadata, and more.

    We will examine how Client ID Metadata Documents (CIMD) allow clients to bring their own identity via DNS, offering authorization servers more control of which agents are able to connect to their servers. We will also cover the implementation patterns for Protected Resource Metadata (RFC 9728) which allows a user to connect to an MCP server using only a single URL Finally, we will cover the "Enterprise-Managed Authorization" extension (Identity Assertion Authorization Grant), explaining how to architect flows that put the Enterprise IdP back in the driver's seat for AI-driven cross-app access.

    This session is designed for architects and developers who need to understand the structural requirements for building enterprise-ready MCP authorization.
    permalink #mcp #oauth #okta
Posted in /presentations using quill.p3k.io

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv