Key Concepts
- OAUTH: A protocol for delegated authorization, allowing applications (clients) to request access to APIs (resource servers) with user consent, mediated by an authorization server.
- OpenID Connect (OIDC): An identity layer built on top of OAUTH that standardizes user authentication and identity information exchange.
- MCP (Model Communication Protocol): A protocol for communication between AI agents and servers.
- Client Credentials Flow: An OAUTH flow where agents communicate with other agents or servers on their own behalf, without user delegation.
- Dynamic Client Registration: A process where agents can request client credentials (client ID and secret) at runtime, rather than through manual pre-registration.
- Push Client Registration: A simplified registration method for public clients using a well-known string identifier.
- PKI (Public Key Infrastructure): Using URLs and cryptographic key pairs to authenticate agents.
- Agent Attestation: Verifying the state of the device and software running on an agent, including the LLM it interacts with.
- Transactional Authorization: Authorizing actions on a transaction-specific basis, with dynamic permissions and constraints.
- Rich Authorization Requests (RAR): A specification for more dynamic and granular authorization requests.
- Chain of Custody: Ensuring security and authorization across multiple API calls and agent interactions.
- OAUTH Token Exchange: A technique for exchanging OAUTH tokens between services within the same domain.
- Identity Assertion Grant: A specification for cross-domain authorization in backend systems.
OAUTH Fundamentals
- OAUTH is a protocol that allows applications (clients) to request access to APIs (resource servers) on behalf of a user.
- The process is mediated by an authorization server, which handles user authentication, consent, and issues access tokens.
- Access tokens are short-lived credentials that the client presents to the resource server to gain access.
- Refresh tokens allow clients to obtain new access tokens without requiring the user to re-authorize.
- Authorization code flow is a common OAUTH flow that involves user delegation and browser-based interfaces.
- OAUTH is often used for "Sign-in with..." functionality, where the API is a user info API that returns user claims (ID, name, email).
- OpenID Connect (OIDC) standardizes this "Sign-in with..." pattern by defining a standard response format for the user info API and introducing the ID token, a JSON Web Token (JWT) containing cryptographically signed user information.
- In OIDC, the authorization server is also referred to as an identity provider (IdP), and applications are known as relying parties.
- The key benefit of OAUTH is that APIs don't have to handle authentication logic; they simply verify the tokens issued by the authorization server.
MCP Authorization: Past, Present, and Future
MCP v1: The NOAUTH Version
- The initial version of MCP lacked any authorization mechanisms.
- It was primarily intended for local MCP servers.
MCP v2 (Draft): OAUTH - The First Attempt
- The initial attempt to add OAUTH to MCP was flawed.
- The specification incorrectly collapsed the authorization server role into the MCP server.
- This approach was criticized for treating the MCP server as both a resource server and an authorization server.
- Christian Posta's blog post highlighted the issues with the MCP authorization spec.
- Aaron Perky also criticized the spec, pointing out the confusion caused by the MCP server handling authorization.
MCP v3 (Draft): OAUTH - The Fix
- The latest draft of the MCP specification models OAUTH correctly, with a separate authorization server.
- MCP servers are now treated as resource servers, simplifying their role to verifying incoming tokens.
- This aligns with standard OAUTH practices and improves security.
The Future of Agent Security with OAUTH
Agent-to-Agent Communication
- The client credentials flow is essential for agents to communicate with each other or with MCP servers on their own behalf, without user delegation.
Agent Identity
- Dynamic client registration is currently used in MCP, but it makes all agents anonymous because the registration request is uncredentialed.
- Push client registration is a simpler alternative for public clients, using a well-known string identifier.
- For authenticating and verifying agent identity, the speaker proposes using URLs and PKI (Public Key Infrastructure).
- Agents can use their URL (e.g., agent.com) as a client identity and sign JWT assertions or HTTP message signatures with their private key, which can be verified using the corresponding public key.
Agent Attestation
- It's important to verify the state of the device and software running on an agent, including the LLM it interacts with.
- Remote attestation and supply chain security techniques can be used to attest to the agent's environment and ensure data is sent to trusted LLMs.
Transactional Authorization
- Traditional OAUTH scopes are often too coarse-grained for agent interactions.
- Transactional authorization allows for authorizing actions on a transaction-specific basis, with dynamic permissions and constraints (e.g., financial transactions with specific amounts).
- Rich Authorization Requests (RAR) is a specification that can be used for more dynamic and granular authorization requests.
Chain of Custody
- It's crucial to ensure security and authorization across multiple API calls and agent interactions.
- OAUTH token exchange can be used to exchange OAUTH tokens between services within the same domain.
- Identity Assertion Grant can be used for cross-domain authorization in backend systems.
- End-to-end visibility is needed as authorization flows along graphs of agents interacting with each other.
Asynchronous Interaction
- OAUTH typically assumes a user is present in front of a browser.
- Agents need a way to reach out to users for additional permissions asynchronously (e.g., via SMS or push notifications).
Voice and Video Interactions
- As AI interacts with users via voice and video, security considerations from real-time communication communities (SIP, XMPP, WebRTC) should be considered.
Conclusion
Securing AI agents requires a comprehensive approach to authorization, building upon OAUTH and extending it to address the unique challenges of agent-to-agent communication, agent identity, attestation, transactional authorization, and asynchronous interactions. The evolution of MCP authorization demonstrates the importance of adhering to established security principles and adapting them to the specific needs of AI-powered systems. Keycard.ai is building an identity and access management platform to address these challenges, using standards-compliant protocols like OAUTH and MCP.
AI summaries can miss context or contain errors. Check important details against the original video.





