Let's Fix OAuth in MCP
aaronparecki.com
aaronparecki.com
The "OAuth 2.0 Protected Resource Metadata" protocol[1] mentioned to enable auth-bootstrapping clients looks like a nice evolution of the ecosystem.
The "Identity Assertion Authorization Grant" at the end[2] was a nice bonus.
[1]: https://datatracker.ietf.org/doc/draft-ietf-oauth-resource-m...
[2]: https://datatracker.ietf.org/doc/draft-parecki-oauth-identit...