SOLFIND
Web Lens
Portal home

Enterprise-Managed Authorization Charter - Model Context Protocol

https://modelcontextprotocol.org/community/interest-groups/enterprise-managed-authorization • 303 KB fetched
Open original page


Enterprise-Managed Authorization Charter - Model Context Protocol Documentation Index Fetch the complete documentation index at: /llms.txt Use this file to discover all available pages before exploring further. Skip to main content Model Context Protocol home page Search... ⌘ K Ask Assistant ⌘ I * Blog * GitHub Search... Navigation Interest Group Charters Enterprise-Managed Authorization Charter Documentation Specification Extensions Registry SEPs Community Get Involved * Contributing to MCP * Contributor Communication * Working and Interest Groups * Group Charter Template Shaping the Protocol * Roadmap * Design Principles * SEP Guidelines Governance * Governance and Stewardship * Contributor Ladder * Feature Lifecycle and Deprecation Policy * SDK Tiering System * Security Policy * Antitrust Policy Working Group Charters * Agents Charter * File Uploads Charter * Filesystems Charter * Inspector V2 Working Group Charter * Interceptors Charter * Registry Charter * SDK Working Group Charter * Server Card Charter * Skills Over MCP Charter * Transports Charter * Triggers and Events Charter Interest Group Charters * Authorization Charter * Enterprise Interest Group Charter * Enterprise-Managed Authorization Charter * Financial Services Charter * Primitive Grouping Charter * Security Charter * Tool Annotations Charter On this page * Group Type * Mission Statement * Scope * In Scope * Out of Scope * Related Groups * Leadership * Membership * Operations * Changelog Interest Group Charters Enterprise-Managed Authorization Charter Copy page Copy page Charter for the MCP Enterprise-Managed Authorization Interest Group. Copy page Copy page As of 2026-08-17 this Interest Group is folded into the Authorization IG . EMA interoperability and deployment progress is presented as agenda slots on the Auth IG call, discussion continues in #auth-ig threads, and #enterprise-managed-auth-ig is archived. This page is kept for reference. ​ Group Type Interest Group ​ Mission Statement The Enterprise-Managed Authorization Interest Group provides a venue for identity-provider vendors, MCP client implementers, and MCP server operators to coordinate on real-world adoption of the Enterprise-Managed Authorization extension ( io.modelcontextprotocol/enterprise-managed-authorization ). The extension’s ID-JAG flow only delivers value when an enterprise IdP, an MCP client, and an MCP server’s authorization server all interoperate end to end — this group exists to gather deployment experience, surface compatibility gaps between independent implementations, and feed validated problems back to the Authorization IG and the ext-auth specification. ​ Scope ​ In Scope * Interoperability reports : documented results of pairing specific IdPs, MCP clients, and MCP authorization servers through the full ID-JAG exchange, including what worked, what required workarounds, and what failed * Conformance scenario input : identifying the assertions an EMA conformance suite should make (ID-JAG validation, audience and issuer checks, claim mapping, account linking, error handling) and contributing scenarios to the conformance repository * Deployment patterns : comparing notes on tenant isolation, admin-consent flows, JIT provisioning, claim-to-permission mapping, and token-lifetime choices observed in production rollouts * IdP capability gaps : cataloguing where existing IdP products cannot yet issue or validate ID-JAGs as specified, so implementers know what to expect and IdP vendors have a shared backlog * Spec clarification requests : collecting ambiguities and underspecified behaviour discovered during implementation and routing them to the ext-auth repository as issues or PRs ​ Out of Scope * Other authorization profiles : Client Credentials, DPoP, Workload Identity Federation, and the core OAuth 2.1 flow belong to the Authorization IG * General enterprise deployment topics : networking, packaging, and host-application rollout concerns that are not specific to the ID-JAG flow * End-user product configuration walk-throughs : the IG discusses patterns, not step-by-step setup for individual IdP or client products. Vendor-reported constraints on what an IdP can or cannot implement are in scope as deployment experience * Competitively sensitive or non-public business information , per the MCP Antitrust Policy ​ Related Groups * Authorization IG : parent group for all MCP authorization work; EMA spec changes are incubated there and this IG’s findings feed its agenda * Security IG : token-audience confusion, issuer validation, and account-linking risks in the ID-JAG flow sit at the boundary between the two groups * SDK Maintainers : SDKs ship the EMA client implementation; interop findings inform cross-SDK behaviour and defaults ​ Leadership Role Name Organization GitHub Term Facilitator Paul Carleton Anthropic @pcarleton Initial Facilitator Aaron Parecki Okta @aaronpk Initial Sponsored by Den Delimarsky ( @localden , Lead Maintainer). ​ Membership Open to anyone; no formal membership or approval step is required to join the channel, attend calls, or contribute. The group particularly seeks participants from enterprise IdP vendors, MCP client implementers shipping EMA support, and MCP server operators integrating with an enterprise IdP. Join the #enterprise-managed-auth-ig channel on the MCP Contributors Discord or open a thread in the Authorization category of GitHub Discussions . Calls are open and attendance is optional — async participation via Discord and GitHub is equally valued. ​ Operations Meeting Frequency Duration Purpose Interop Call Every 2 weeks 45 min Deployment reports, compatibility-matrix review, spec-feedback triage An agenda is shared in #enterprise-managed-auth-ig ahead of each call. Meeting notes are posted to the Authorization category in GitHub Discussions . Discord: #enterprise-managed-auth-ig · invite ​ Changelog Date Change 2026-08-17 Folded into the Authorization IG; channel archived 2026-06-16 Initial charter Was this page helpful? Yes No Enterprise Interest Group Charter Financial Services Charter github Assistant Responses are generated using AI and may contain mistakes.

Links found on this page

  1. /llms.txt [direct]
  2. Skip to main content [direct]
  3. Model Context Protocol home page [direct]
  4. Blog [direct]
  5. GitHub [direct]
  6. Documentation [direct]
  7. Specification [direct]
  8. Extensions [direct]
  9. Registry [direct]
  10. SEPs [direct]
  11. Community [direct]
  12. Contributor Communication [direct]
  13. Working and Interest Groups [direct]
  14. Group Charter Template [direct]
  15. Roadmap [direct]
  16. Design Principles [direct]
  17. SEP Guidelines [direct]
  18. Governance and Stewardship [direct]
  19. Contributor Ladder [direct]
  20. Feature Lifecycle and Deprecation Policy [direct]
  21. SDK Tiering System [direct]
  22. Security Policy [direct]
  23. Antitrust Policy [direct]
  24. Agents Charter [direct]
  25. File Uploads Charter [direct]
  26. Filesystems Charter [direct]
  27. Inspector V2 Working Group Charter [direct]
  28. Interceptors Charter [direct]
  29. Registry Charter [direct]
  30. SDK Working Group Charter [direct]
  31. Server Card Charter [direct]
  32. Skills Over MCP Charter [direct]
  33. Transports Charter [direct]
  34. Triggers and Events Charter [direct]
  35. Authorization Charter [direct]
  36. Enterprise Interest Group Charter [direct]
  37. Financial Services Charter [direct]
  38. Primitive Grouping Charter [direct]
  39. Security Charter [direct]
  40. Tool Annotations Charter [direct]
  41. Enterprise-Managed Authorization extension [direct]
  42. ext-auth [direct]
  43. conformance [direct]
  44. @pcarleton [direct]
  45. @aaronpk [direct]
  46. @localden [direct]
  47. GitHub Discussions [direct]
  48. #enterprise-managed-auth-ig [direct]
  49. invite [direct]