MCP Adds Enterprise-Managed Authorization — Zero-Touch OAuth via Okta
Published 2026-06-18Ingested 2026-06-19Agentic AIHigh⭐ Timeline Candidate
Summary
The Model Context Protocol project introduced Enterprise-Managed Authorization (EMA), an official MCP extension that lets organizations centrally provision MCP server access through their identity provider rather than forcing every user through per-app OAuth consent flows. Built on Okta's Cross App Access (XAA) protocol — an OAuth extension for securing agent-to-app and app-to-app access — EMA issues users an Identity Assertion JWT Authorization Grant from their IdP, which is exchanged for an MC
Radar Context
Alignment: Reinforces current position
Related Positions: Agentic Workflows, AI Governance and Risk, Enterprise AI Delivery, Multi-Model, Multi-Vendor Strategy
Related Partnerships: Anthropic (Claude)
mcpenterprise-authoktaoauthagent-governanceworkload-identity-federationanthropiczero-touch