{"schema_version":"newruntime-agent-readable-v0.2","type":"post","stable_id":"post:mcp-oauth-authorization-boundary","slug":"mcp-oauth-authorization-boundary","title":"MCP and OAuth Put Agent Authorization on the Critical Path","description":"PropelAuth's MCP and OAuth 2.1 deep dive shows that agent protocols need explicit user, client, server, and scope boundaries.","retrieval_nugget":"PropelAuth's MCP and OAuth 2.1 deep dive shows that agent protocols need explicit user, client, server, and scope boundaries. The PropelAuth deep dive is a reminder that MCP cannot stay at the level of convenient tool calls. Once an agent can reach real user data or production systems, the protocol needs a clear authorization story: who is the user, who.","status":"published","published_at":"2026-07-29","updated_at":"2026-07-29","record_date":"2026-07-29","date_kind":"published_at","topics":["agent-protocols","ai-security"],"source_urls":["https://www.propelauth.com/post/oauth-2-1-and-mcp-deep-dive"],"visuals":[{"id":"mcp-oauth-authorization-boundary","kind":"editorial-diagram","role":"hero","src":"https://newruntime.com/images/posts/mcp-oauth-authorization-boundary.webp","alt":"Hand-drawn authorization boundary from user intent and agent client through token scopes and consent into a protected resource.","caption":"MCP tool calls become infrastructure only when identity, token, scopes, consent, logs, and revocation are explicit boundaries.","credit":"New Runtime synthesis","source_url":"https://www.propelauth.com/post/oauth-2-1-and-mcp-deep-dive","generated_with":"nano-banana-style-imagegen","width":1600,"height":900,"legend":[]}],"routes":{"html":"https://newruntime.com/posts/mcp-oauth-authorization-boundary/","markdown":"https://newruntime.com/posts/mcp-oauth-authorization-boundary.md","json":"https://newruntime.com/posts/mcp-oauth-authorization-boundary.json"},"source_format":"markdown","next_reads":[{"type":"topic","path":"/topics/agent-protocols/","reason":"Explore the agent protocols topic hub.","url":"https://newruntime.com/topics/agent-protocols/","title":"Agent Protocols - New Runtime","media_type":"text/html"},{"type":"topic","path":"/topics/ai-security/","reason":"Explore the ai security topic hub.","url":"https://newruntime.com/topics/ai-security/","title":"AI Security - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/posts/openai-hugging-face-incident-followup/","reason":"Shares ai security.","url":"https://newruntime.com/posts/openai-hugging-face-incident-followup/","title":"The OpenAI Hugging Face Follow-Up Is Really About Control Boundaries","media_type":"text/html"},{"type":"related_material","path":"/posts/raptor-loop-hunt-security-agent-loop/","reason":"Shares ai security.","url":"https://newruntime.com/posts/raptor-loop-hunt-security-agent-loop/","title":"RAPTOR Loop Hunt Packages Security Hunting as an Agent Skill","media_type":"text/html"},{"type":"related_material","path":"/posts/open-secure-ai-alliance-open-defense-stack/","reason":"Shares ai security.","url":"https://newruntime.com/posts/open-secure-ai-alliance-open-defense-stack/","title":"Open Secure AI Alliance Turns the AI-Safety Fight Into a Stack Question","media_type":"text/html"}]}
