Enterprise-Managed Authorization Charter - Model Context Protocol
https://modelcontextprotocol.org/community/interest-groups/enterprise-managed-authorization • 303 KB fetched Open original page
Enterprise-Managed Authorization Charter - Model Context Protocol
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Skip to main content
Model Context Protocol home page
Search...
⌘ K Ask Assistant ⌘ I
* Blog
* GitHub
Search...
Navigation
Interest Group Charters
Enterprise-Managed Authorization Charter
Documentation
Specification
Extensions
Registry
SEPs
Community
Get Involved
* Contributing to MCP
* Contributor Communication
* Working and Interest Groups
* Group Charter Template
Shaping the Protocol
* Roadmap
* Design Principles
* SEP Guidelines
Governance
* Governance and Stewardship
* Contributor Ladder
* Feature Lifecycle and Deprecation Policy
* SDK Tiering System
* Security Policy
* Antitrust Policy
Working Group Charters
* Agents Charter
* File Uploads Charter
* Filesystems Charter
* Inspector V2 Working Group Charter
* Interceptors Charter
* Registry Charter
* SDK Working Group Charter
* Server Card Charter
* Skills Over MCP Charter
* Transports Charter
* Triggers and Events Charter
Interest Group Charters
* Authorization Charter
* Enterprise Interest Group Charter
* Enterprise-Managed Authorization Charter
* Financial Services Charter
* Primitive Grouping Charter
* Security Charter
* Tool Annotations Charter
On this page
* Group Type
* Mission Statement
* Scope
* In Scope
* Out of Scope
* Related Groups
* Leadership
* Membership
* Operations
* Changelog
Interest Group Charters
Enterprise-Managed Authorization Charter
Copy page Copy page
Charter for the MCP Enterprise-Managed Authorization Interest Group.
Copy page Copy page
As of 2026-08-17 this Interest Group is folded into the Authorization
IG . EMA interoperability and deployment
progress is presented as agenda slots on the Auth IG call, discussion
continues in #auth-ig threads, and #enterprise-managed-auth-ig is
archived. This page is kept for reference.
Group Type
Interest Group
Mission Statement
The Enterprise-Managed Authorization Interest Group provides a venue for identity-provider vendors, MCP client implementers, and MCP server operators to coordinate on real-world adoption of the Enterprise-Managed Authorization extension ( io.modelcontextprotocol/enterprise-managed-authorization ). The extension’s ID-JAG flow only delivers value when an enterprise IdP, an MCP client, and an MCP server’s authorization server all interoperate end to end — this group exists to gather deployment experience, surface compatibility gaps between independent implementations, and feed validated problems back to the Authorization IG and the ext-auth specification.
Scope
In Scope
* Interoperability reports : documented results of pairing specific IdPs, MCP clients, and MCP authorization servers through the full ID-JAG exchange, including what worked, what required workarounds, and what failed
* Conformance scenario input : identifying the assertions an EMA conformance suite should make (ID-JAG validation, audience and issuer checks, claim mapping, account linking, error handling) and contributing scenarios to the conformance repository
* Deployment patterns : comparing notes on tenant isolation, admin-consent flows, JIT provisioning, claim-to-permission mapping, and token-lifetime choices observed in production rollouts
* IdP capability gaps : cataloguing where existing IdP products cannot yet issue or validate ID-JAGs as specified, so implementers know what to expect and IdP vendors have a shared backlog
* Spec clarification requests : collecting ambiguities and underspecified behaviour discovered during implementation and routing them to the ext-auth repository as issues or PRs
Out of Scope
* Other authorization profiles : Client Credentials, DPoP, Workload Identity Federation, and the core OAuth 2.1 flow belong to the Authorization IG
* General enterprise deployment topics : networking, packaging, and host-application rollout concerns that are not specific to the ID-JAG flow
* End-user product configuration walk-throughs : the IG discusses patterns, not step-by-step setup for individual IdP or client products. Vendor-reported constraints on what an IdP can or cannot implement are in scope as deployment experience
* Competitively sensitive or non-public business information , per the MCP Antitrust Policy
Related Groups
* Authorization IG : parent group for all MCP authorization work; EMA spec changes are incubated there and this IG’s findings feed its agenda
* Security IG : token-audience confusion, issuer validation, and account-linking risks in the ID-JAG flow sit at the boundary between the two groups
* SDK Maintainers : SDKs ship the EMA client implementation; interop findings inform cross-SDK behaviour and defaults
Leadership
Role Name Organization GitHub Term
Facilitator Paul Carleton Anthropic @pcarleton Initial
Facilitator Aaron Parecki Okta @aaronpk Initial
Sponsored by Den Delimarsky ( @localden , Lead Maintainer).
Membership
Open to anyone; no formal membership or approval step is required to join the channel, attend calls, or contribute. The group particularly seeks participants from enterprise IdP vendors, MCP client implementers shipping EMA support, and MCP server operators integrating with an enterprise IdP.
Join the #enterprise-managed-auth-ig channel on the MCP Contributors Discord or open a thread in the Authorization category of GitHub Discussions . Calls are open and attendance is optional — async participation via Discord and GitHub is equally valued.
Operations
Meeting Frequency Duration Purpose
Interop Call Every 2 weeks 45 min Deployment reports, compatibility-matrix review, spec-feedback triage
An agenda is shared in #enterprise-managed-auth-ig ahead of each call. Meeting notes are posted to the Authorization category in GitHub Discussions .
Discord: #enterprise-managed-auth-ig · invite
Changelog
Date Change
2026-08-17 Folded into the Authorization IG; channel archived
2026-06-16 Initial charter
Was this page helpful?
Yes No
Enterprise Interest Group Charter
Financial Services Charter
github
Assistant
Responses are generated using AI and may contain mistakes.
Links found on this page
- /llms.txt [direct]
- Skip to main content [direct]
- Model Context Protocol home page [direct]
- Blog [direct]
- GitHub [direct]
- Documentation [direct]
- Specification [direct]
- Extensions [direct]
- Registry [direct]
- SEPs [direct]
- Community [direct]
- Contributor Communication [direct]
- Working and Interest Groups [direct]
- Group Charter Template [direct]
- Roadmap [direct]
- Design Principles [direct]
- SEP Guidelines [direct]
- Governance and Stewardship [direct]
- Contributor Ladder [direct]
- Feature Lifecycle and Deprecation Policy [direct]
- SDK Tiering System [direct]
- Security Policy [direct]
- Antitrust Policy [direct]
- Agents Charter [direct]
- File Uploads Charter [direct]
- Filesystems Charter [direct]
- Inspector V2 Working Group Charter [direct]
- Interceptors Charter [direct]
- Registry Charter [direct]
- SDK Working Group Charter [direct]
- Server Card Charter [direct]
- Skills Over MCP Charter [direct]
- Transports Charter [direct]
- Triggers and Events Charter [direct]
- Authorization Charter [direct]
- Enterprise Interest Group Charter [direct]
- Financial Services Charter [direct]
- Primitive Grouping Charter [direct]
- Security Charter [direct]
- Tool Annotations Charter [direct]
- Enterprise-Managed Authorization extension [direct]
- ext-auth [direct]
- conformance [direct]
- @pcarleton [direct]
- @aaronpk [direct]
- @localden [direct]
- GitHub Discussions [direct]
- #enterprise-managed-auth-ig [direct]
- invite [direct]
|
|