new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

MCP · Building servers and clients · all subjects

security: oauth & authorization

5 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

URL-based client registration with OAuth Client ID Metadata Documents

SEP-991 introduced URL-based client registration using OAuth Client ID Metadata Documents as an alternative to Dynamic Client Registration. Clients can now provide their own client ID that is a URL pointing to a JSON document the client manages describing properties of the client. This simplifies authorization flows by eliminating the need for OAuth proxies or complex per-user registration processes.

SEP-835 Default scopes definition in authorization

SEP-835 defines default scopes in the authorization specification as part of the November 2025 MCP specification release.

OAuth client credentials authorization extension SEP-1046

SEP-1046 introduces OAuth client credentials support for machine-to-machine authorization as an authorization extension built on the core MCP protocol.

Enterprise IdP policy controls and Cross App Access SEP-990

SEP-990 introduces enterprise IdP policy controls for MCP OAuth flows through the Cross App Access extension. This enables users within an enterprise to sign in to the MCP client once and immediately get access to every authorized MCP server without additional authorization prompts.

URL mode elicitation for secure out-of-band credential flows SEP-1036

SEP-1036 introduces URL mode elicitation allowing MCP servers to send users to secure OAuth flows in their browser for credential acquisition. The credentials never transit through the MCP client; instead, the server obtains necessary tokens directly after the user completes the flow. This enables secure credential collection, external OAuth flows, and PCI-compliant payment processing scenarios.

Give your agent this brain