← Back to all topics

Posts about "OAuth/OIDC"

Enterprise-Managed Authorization for MCP: what it actually does, and what it leaves to you

MCP enterprise-managed authorization (EMA) lets the corporate identity provider decide which MCP servers employees can reach, with no per-server consent prompts. A practical, spec-accurate guide to the ID-JAG flow with a build checklist, and a hard line between what EMA secures (the connection) and what it leaves to you (per-action authorization).

Agent Access Control: Identity Mesh and Secure AI agents (act on behalf of humans and services)

Agent Access Control: Pilot → Production, Part 1 of 6. Why production AI agents must execute on behalf of a human or service identity, not with a shared "agent token." Introduces Subject/Actor/Authority and per-action scoped access for auditable tool calls, plus the Identity Mesh concept for consistent per-action policy decisions across tools.

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

Principal Software Engineer and Tech Lead with a track record of leading high-performing engineering teams and delivering scalable, end-to-end technology solutions. With experience across web, mobile, and backend systems, I help companies make smart architectural decisions, scale efficiently, and align technical strategy with business goals.

© 2026 Ehsan Hosseini. All rights reserved.