3 ms·
MCP new spec has to an extent covered auth. But the MCPs are yet to adopt to that.
by amitksingh1490 1y ago
MCP new spec has to an extent covered auth. But the MCPs are yet to adopt to that.
- simonw 1y agoAuth doesn't protect against confused deputy attacks, which is a common problem exposed by MCP and other LLM tool systems. https://en.m.wikipedia.org/wiki/Confused_deputy_problem https://en.m.wikipedia.org/wiki/Confused_deputy_problem
- bitweis 1y ago100% - especially when Auth stands for just Authentication. Simple RBAC authorization also won't take us far. But Fine-grained Permissions(e.g. OPA, Cedar, OpenFGA, Permit.io) with ReBAC giving ai-agents Zero standing permissions, and only deriving on the fly the least privilege they need / got consent for, can dramatically reduce the problem