47°F

Aaron Parecki

  • Articles
  • Notes
  • Photos

#mcp

  • Las Vegas (LAS) to Portland (PDX)
    June 18, 2026 from 6:26pm to 8:47pm (-0700)
    Alaska Flight 779
    Portland Intl in Portland
    permalink #okta #identiverse #oauth #mcp
  • Identiverse
    Jun
    15
    Jun
    …
    Jun
    18
    June 15-18, 2026
    4 days
    Mandalay Bay
    Las Vegas, Nevada, US
    permalink #okta #identiverse #oauth #mcp
  • Portland (PDX) to Las Vegas (LAS)
    June 14, 2026 from 5:50pm to 8:15pm (-0700)
    Alaska Flight 531
    Mc Carran Intl in Las Vegas
    permalink #okta #identiverse #mcp #oauth
  • Newark (EWR) to Portland (PDX)
    April 4, 2026 from 5:38pm (-0400) to 8:50pm (-0700)
    Alaska Flight 290
    Portland Intl in Portland
    permalink #okta #mcp
  • MCP Dev Summit
    Apr
    2
    Apr
    3
    April 2-3, 2026
    New York Marriott Marquis
    New York, New York, US
    permalink #mcp #okta
  • New York
    Mar
    30
    Apr
    4
    March 30 through April 4, 2026
    6 days
    New York
    New York, New York, US
    permalink #okta #mcp #mcpdevsummit
  • Portland (PDX) to New York (JFK)
    March 30, 2026 from 7:00am (-0700) to 3:26pm (-0400)
    Alaska Flight 18
    John F Kennedy Intl in New York
    permalink #okta #mcp #mcpdevsummit
  • Aaron Parecki
    If you’re struggling to get AI agents past enterprise security reviews, join me tomorrow for a session on how Cross App Access (XAA) brings managed authorization to MCP!

    I'll be joined by Sohail Pathan to show off our Cross App Access playground and give a live demo of how the protocol works!

    Tomorrow - February 18, 2026 (8 AM PT)

    πŸ‘‰ https://www.brighttalk.com/webcast/14899/661521?utm_source=apk_social&utm_medium=brighttalk&utm_campaign=661521
    Portland, Oregon • 43°F
    1 repost
    Tue, Feb 17, 2026 3:17pm -08:00 #okta #oktadev #xaa #mcp #oauth #enterprisesecurity
  • Making OAuth Scale Securely for MCPs - Application Security Weekly

    The MCP standard gave rise to dreams of interconnected agents and nightmares of what those interconnected agents would do with unfettered access to APIs, data, and local systems. Aaron Parecki explains how OAuth’s new Client ID Metadata Documents spec provides more security for MCPs and the reasons why the behavior and design of MCPs required a new spec like this.
    continue reading...
    Tue, Dec 9, 2025 11:30am -08:00 #mcp #oauth
  • Aaron Parecki
    The new MCP spec just dropped! πŸŽ‰

    There's too many new things to get into everything, but there are two big changes I am most excited about πŸ‘€

    πŸ“ Client ID Metadata Documents (CIMD) - a simpler way to manage client registrations, clients describe themselves with a URL they control
    πŸ” Enterprise-Managed Authorization extension (aka Cross App Access) - eliminate the OAuth redirect and get tokens for an MCP server by requesting them from the enterprise IdP

    It's been great working on this with folks like Den Delimarsky, Paul Carleton, David Soria Parra, Nick Cooper, Tyler Leonhardt, and more!

    Read more about what these mean for you in my full post
    πŸ‘‰ https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update
    Portland, Oregon • 44°F
    1 like
    Tue, Nov 25, 2025 3:11pm -08:00 #oauth #cimd #xaa #mcp
  • Cross App Access extends MCP to bring enterprise-grade security to AI agent interactions (www.okta.com)
    Tue, Nov 25, 2025 2:36pm -08:00 #mcp #oauth #xaa
  • Arcade.dev and Anthropic advance MCP with new secure authorization flow - SiliconANGLE (siliconangle.com)
    Tue, Nov 25, 2025 2:36pm -08:00 #mcp #oauth
  • Client Registration and Enterprise Management in the November 2025 MCP Authorization Spec

    The new MCP authorization spec is here! Today marks the one-year anniversary of the Model Context Protocol, and with it, the launch of the new 2025-11-25 specification.
    continue reading...
    1 like 1 mention
    Tue, Nov 25, 2025 1:25pm -08:00 #cimd #oauth #mcp #ai
  • feature: Add support for Client ID Metadata Documents (CIMD) by chipgpt · Pull Request #13 · chipgpt/full-stack-saas-mcp (github.com)
    Mon, Nov 3, 2025 8:58pm -05:00 #oauth #cimd #mcp
  • Why industry alignment on open standards will be key to unlocking a secure AI future - Application Security Weekly

    Open standards are essential for building secure, interoperable, and trustworthy AI ecosystems. Aaron Parecki, Director of Identity Standards at Okta, discusses the IPSIE working group’s efforts to create consistent identity security profiles, why protocols like MCP and A2A require authentication frameworks to safely manage AI agents’ access and communication, and how Cross App Access provides centralized control over AI-driven and app-to-app interactions.
    continue reading...
    Thu, Sep 25, 2025 10:00am -07:00 #oauth #ipsie #okta #oktane #asw #mcp
  • Aaron Parecki
    Had a great time talking about OAuth for MCP at Microsoft Channel 9!
    Redmond, Washington, USA
    Tue, Jul 29, 2025 11:59am -07:00 #oauth #mcp #365
  • Portland (PDX) to Seattle (SEA)
    July 28, 2025 from 5:35pm to 6:30pm (-0700)
    Alaska Flight 2241
    Seattle Tacoma Intl in Seattle
    permalink #okta #mcp
  • Seattle and San Francisco
    Jul
    28
    Jul
    …
    Jul
    31
    July 28-31, 2025
    4 days
    Okta
    San Francisco, California, US
    permalink #okta #mcp
  • Seattle (SEA) to Portland (PDX)
    July 11, 2025 from 6:02pm to 6:58pm (-0700)
    Alaska Flight 3461
    Portland Intl in Portland
    permalink #okta #oauth #mcp
  • OAuth/MCP Working Meeting
    Jul
    11
    July 11, 2025 9:00am - 4:00pm (-0700)
    1918 Eighth Avenue
    Seattle, Washington, US
    permalink #oauth #okta #mcp
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • πŸŽ₯ YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • βš™οΈ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2026 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv