← All flows

Beyond the flows

OAuth in the AI era

Last reviewed: 28 September 2026. This area moves quickly, so check the linked sources for the latest.

AI agents call APIs for people, often for a long time and sometimes through other agents. OAuth was designed for a person clicking in a browser, so the community is reusing what works and adding what is missing. There is no new "AI OAuth". Most of the work is careful use of existing pieces.

How MCP uses OAuth

The Model Context Protocol (MCP) lets an AI app connect to tools and data on a server. For remote servers, its authorization rules are built on OAuth. The MCP server acts as the resource server, and the AI app is the client.

  1. 01Discovery. The MCP server publishes Protected Resource Metadata (RFC 9728) naming its authorization server. The client then reads that server's metadata (RFC 8414).
  2. 02Client identity. The client is known by a Client ID Metadata Document (a URL), a pre-registered ID, or Dynamic Client Registration (RFC 7591) as a fallback.
  3. 03Authorization. The standard Authorization Code flow with PKCE, as in OAuth 2.1.
  4. 04Audience. The client sends a resource parameter (RFC 8707), and the server must reject tokens that were not issued for it.

The rules changed between MCP versions. The 2025-11-25 version made Client ID Metadata Documents the recommended way to identify a client. The 2026-07-28 version deprecates Dynamic Client Registration (it still works for now), adds issuer checking (RFC 9207) and clarifies scope step-up. The release announcement has the summary. MCP is a spec still changing, so read the current version.

Published standards

These are finished and stable.

Drafts still in progress

An Internet-Draft is work in progress. It can change or never be published, so do not treat it as a standard.

Related: enterprise-managed authorization is an MCP extension that combines Token Exchange with the Identity Assertion JWT Authorization Grant.

Open problems

The OpenID Foundation's whitepaper Identity Management for Agentic AI is a good overview of the wider questions.

What to watch

Follow the OAuth working group documents for the current status of every draft above.