AI Briefing
KO

Zero-Touch OAuth for MCP

·2026.06.19 06:54

Key point

An EMA extension supporting centralized authorization management in enterprise MCP environments has been released.

Details

The Enterprise-Managed Authorization (EMA) extension for the Model Context Protocol (MCP) has been released as a stable version. Previously, MCP authentication required users to individually approve each server, which was cumbersome, but EMA was designed to solve this.

Key Features and Benefits:

  • Zero-Touch Setup: Once an admin configures permissions through the enterprise's Identity Provider (IdP), users can instantly access all connected MCP servers simply by logging in, without any separate individual approval process.
  • Centralized Policy Management: Security teams can centrally control and audit MCP server access permissions through the enterprise's IdP.
  • Prevention of Account Mixing: Clearly distinguishes between personal and enterprise accounts to prevent data from being leaked incorrectly.

Ecosystem Adoption Status:

  • Identity Providers: Okta is participating as the first supporting vendor, enabling provisioning of MCP access permissions through Cross App Access (XAA).
  • Clients: Anthropic has implemented this extension in Claude, Claude Code, and Cowork, allowing enterprise users to access tools and data according to admin permissions.
  • Others: Microsoft and various MCP servers are adopting this standard.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.