We really appreciate your feedback
For policy updates, the biscuit token store reference to the role and optionally a tenant. This means that any extensions or restrictions you make to the policy will be applied directly
For token invalidation, you can either invalidate any token generated after a certain period or manage a blacklist for individual tokens (this is not yet implemented). Regarding rotation, we are currently exploring the use of standard MCP OAuth to deliver biscuit tokens per session. This process is ongoing and will be compatible only with HTTP deployments of Cori.
Concerning extensibility, the current policy format aims to cover 80% of standard use cases. For custom workflows, we are developing a dedicated component that will allow the orchestration of multiple services, whether APIs or MCP servers