I am very curious how many MCP servers will actually implement all of this: "MCP authorization today is built around a person approving access in a browser. That works well for interactive clients, but more and more of the callers are agents running as cloud workloads with their own identity, acting on behalf of a user who isn’t present, or delegating narrower authority to sub-agents. We want MCP servers to have a st…
Authorization for sub-entities is what is needed. Having to define what an agent can do when it identifies on my behalf is cumbersome, especially when you start to get specialised agents. Pattern based would be too easy for AI to game, but there's got to be a service independent way to limit permissions based on role. I am Jack's right ear - awesome you get to hear stuff. I am jack's right hand - great you get to inp…
Re: New MCP Roadmap
#191[dead]