<description>&lt;p&gt;The MCP standard gave rise to dreams of interconnected agents and nightmares of what those interconnected agents would do with unfettered access to APIs, data, and local systems. Aaron Parecki explains how OAuth's new Client ID Metadata Documents spec provides more security for MCPs and the reasons why the behavior and design of MCPs required a new spec like this.&lt;/p&gt; &lt;p&gt;Segment resources:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a rel="noopener" target="_blank" href= "https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update"&gt; https://aaronparecki.com/2025/11/25/1/mcp-authorization-spec-update&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel="noopener" target="_blank" href= "https://www.ietf.org/archive/id/draft-ietf-oauth-client-id-metadata-document-00.html"&gt; https://www.ietf.org/archive/id/draft-ietf-oauth-client-id-metadata-document-00.html&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel="noopener" target="_blank" href= "https://oauth.net/cross-app-access/"&gt;https://oauth.net/cross-app-access/&lt;/a&gt;&lt;/li&gt; &lt;li&gt;&lt;a rel="noopener" target="_blank" href= "https://oauth.net/2/oauth-best-practice/"&gt;https://oauth.net/2/oauth-best-practice/&lt;/a&gt;&lt;/li&gt; &lt;/ul&gt; &lt;p&gt;Visit &lt;a rel="noopener" target="_blank" href= "https://www.securityweekly.com/asw"&gt;https://www.securityweekly.com/asw&lt;/a&gt; for all the latest episodes!&lt;/p&gt; &lt;p&gt;Show Notes: &lt;a rel="noopener" target="_blank" href= "https://securityweekly.com/asw-360"&gt;https://securityweekly.com/asw-360&lt;/a&gt;&lt;/p&gt;</description>

Application Security Weekly (Audio)

Security Weekly Productions

Making OAuth Scale Securely for MCPs - Aaron Parecki - ASW #360

DEC 9, 202567 MIN
Application Security Weekly (Audio)

Making OAuth Scale Securely for MCPs - Aaron Parecki - ASW #360

DEC 9, 202567 MIN

Description

The MCP standard gave rise to dreams of interconnected agents and nightmares of what those interconnected agents would do with unfettered access to APIs, data, and local systems. Aaron Parecki explains how OAuth's new Client ID Metadata Documents spec provides more security for MCPs and the reasons why the behavior and design of MCPs required a new spec like this.

Segment resources:

Visit https://www.securityweekly.com/asw for all the latest episodes!

Show Notes: https://securityweekly.com/asw-360