Fetching from the wire…
Security2026-06-29 · source-backed
The new authorization spec, co-developed by Anthropic, Arcade, Microsoft, and Okta/Auth0, classifies MCP servers as OAuth 2.1 resource servers and standardizes audience binding via Resource Indicators (RFC 8707) and token exchange via RFC 8693. Aembit's writeup explains the choice of delegation over impersonation, so the agent stays distinguishable from the user it acts for. The two-identity model enforces an intersection rule: a compromised agent can only ever do what both the agent and the user are allowed to do. If you're shipping multi-user agents, stop minting broad agent-owned keys and move to on-behalf-of scoped, short-lived tokens per call.
Each link below shares sources, entities, or timing with this story.
MCP uses OAuth / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, Microsoft, Okta; overlapping topics (anthropic, auth, server).
MCP uses OAuth / Shared entities / Shared topic / What happened next / Tension
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, Microsoft; overlapping topics (agent, spec).
MCP uses OAuth / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, Microsoft; overlapping topics (auth, server).
MCP uses OAuth / Shared entities / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, Microsoft, RFC; picks up the Anthropic thread on 2026-07-14.
MCP uses OAuth / Shared entities / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP; overlapping topics (agent, anthropic, server, token).
MCP uses OAuth / Shared entities / Shared topic / What happened next
Linked by a graph relationship (MCP uses OAuth); both cover MCP, Microsoft, OAuth; overlapping topics (agent, keys).
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, RFC; overlapping topics (server, spec).
Linked by a graph relationship (MCP uses OAuth); both cover Anthropic, MCP, Microsoft; overlapping topics (agent, spec).