Zero-Touch OAuth for MCP

(blog.modelcontextprotocol.io)

42 points | by niyikiza 1 hour ago

5 comments

  • RVuRnvbM2e 24 minutes ago
    I don't quite understand the advantage of this over regular oauth. I think I need an example comparison of the authz flows.
    • maxwellg 7 minutes ago
      In regular OAuth, end users consent to share their data with applications individually. This makes sense for consumer usecases, where the end users own their data. But it doesn't make sense for many business usecases, where the business is the entity that should control data sharing and access, not the end user. As an employee at Acme, I shouldn't decide to link my Acme Google Drive data to Claude or ChatGPT, that should be the decision of my IT Department.

      Enterprise-Managed OAuth, or Cross App Access (XAA), brings this IT-Admin centrally controlled sharing model into the OAuth framework so it works with the existing ecosystem.

      There's also a great UX benefit from moving data sharing consent management from employees to IT Admins - it means that employees don't need to sit through a bunch of OAuth flows to link their accounts together. Their IT Admin has already set up all the sharing controls. Everything plugs in together and should Just Work from day one. Think joining a new company on the first day and your Slack is already linked to your Zoom, your Drive, your Calendar, etc...

      • amluto 2 minutes ago
        This is bonkers.

        Sure, if I’m a business, I will make a business decision to share, or not share, some resource with ChatGPT. But, if I do decide to share something with ChatGPT, I absolutely do NOT want it shared with every single ChatGPT thread, more or less how I don’t want it shared with every single tab an employee has open in a browser.

  • lorecore 13 minutes ago
    Auth has been a wild journey in MCP. It really is a valuable differentiator to things like Skills for enterprises though. Congrats to the team on the ship.
  • paulddraper 22 minutes ago
    "Watson you have a blazing talent for observing the obvious" - Sherlock Homes
  • brap 20 minutes ago
    I thought we’re over this collective delusion called MCP
    • isubkhankulov 1 minute ago
      MCP is just an API designed to be token frugal
  • Jimmy0252 1 hour ago
    [flagged]
    • idoma 1 hour ago
      thank you mr. LLM
      • takethebus 55 minutes ago
        my account is too new I can't flag them :/