Loading…
2026 September 10-11 | Tokyo, Japan
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Thursday September 10, 2026 10:40 - 11:05 JST
Authorization in MCP has been through a number of revisions in the past year. Some major (remember when the authorization server and resource server were expected to be the same?) and some minor. As the specification has stabilized, it can be difficult to know: Am I doing it right?

In this talk we'll briefly recap where MCP Auth came from and where it is now, and then we'll dig into Auth best practices based on evolving discussions and connecting Claude.ai to loads of MCP servers in practice.

We'll cover things like: client registration, progressive authz with challenges, and enterprise managed auth to leverage existing SSO connections.

We'll also explore the latest extensions in development and how to put them together into a cohesive solution for human-in-the-loop but also agentic and on-behalf-of flows.

Lastly, we'll cover how to leverage MCP's conformance testing suite to see how closely you're following best practices, using either client, server or authorization server test suites.
Speakers
avatar for Paul Carleton

Paul Carleton

Member of Technical Staff, Anthropic
Paul Carleton is a Core Maintainer of the Model Context Protocol and Auth Nerd at Anthropic, where he leads auth implementations across Anthropic's clients and the TypeScript and Python SDKs. He drives MCP conformance testing efforts to ensure consistent behavior across the ecosy... Read More →
Thursday September 10, 2026 10:40 - 11:05 JST
Hall 1F
  MCPCon

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link