
< session />
Thu, April 29Reliability, Observability & SecurityAI-Native SoftwareBackend Engineering & Runtimes
When an AI agent calls a tool, someone’s authority is being used. But whose? The user who asked, the agent itself, or the platform running it? Get that wrong, and a helpful assistant can become a confused deputy with access to far more than intended.
In this session, you will explore how the Model Context Protocol addresses this problem through its authorization specification, including changes introduced in the July 2026 revision. You will walk through the complete authorization flow step by step, including OAuth 2.1 with PKCE, protected resource metadata, resource indicators that prevent tokens from being replayed against the wrong server, and issuer validation. You will also examine the move to stateless MCP, the deprecation of Dynamic Client Registration in favour of Client ID Metadata Documents, and tighter requirements around issuers and credential binding.
The session then moves beyond the authorization handshake to a decision the specification cannot make for you: whether a particular tool call, with its particular arguments, should actually be allowed. You will leave with a clear mental model, a reusable sequence diagram of the complete flow, and a checklist for building MCP servers that know exactly who they are working for.
What You Will Learn
How authorization works across users, agents, platforms, and MCP servers
How OAuth 2.1 with PKCE, protected resource metadata, resource indicators, and issuer validation fit together
What the July 2026 MCP authorization changes mean for identity and trust
How to reason about whether a particular agent tool call and its arguments should be authorised
Who Should Attend
AI Engineers, Security Engineers, Platform Engineers, Software Architects, Backend Developers, and practitioners building MCP servers or agent systems that invoke external tools.
< speaker_info />
Brent Laster is a global trainer, author, and speaker on open-source technologies, as well as an experienced developer, manager, and director. He is also the founder and president of Tech Skills Transformations, LLC – a company dedicated to making technology understandable and usable. Throughout his career in software development and management, Brent has always made time to learn and develop both technical and leadership skills and share them with others. He believes that regardless of the topic or technology, there’s no substitute for the excitement and sense of potential that come from providing others with the knowledge they need to accomplish their goals.