MCP Adds Enterprise-Managed Authorization: One Login, Every Connector Ready

·Toolin Editorial Team

Model Context Protocol ships the Enterprise-Managed Authorization extension: enterprises can centrally govern MCP Server access through IdPs like Okta, and users connect on first login with zero configuration.

MCP Adds Enterprise-Managed Authorization: One Login, Every Connector Ready

If you're rolling out MCP (Model Context Protocol) inside an enterprise, the most painful part probably isn't connecting Servers — it's authorization: every employee has to walk through OAuth separately for every MCP Server, security teams have no way to audit centrally, and personal and work accounts easily get mixed up. The newly released Enterprise-Managed Authorization (EMA) extension from MCP exists to fix exactly this — it's already stable, and Anthropic, Microsoft, and Okta are all using it.

What EMA Solves

Standard MCP authorization is user-scoped: each user authorizes each Server individually. In enterprise settings that has three hard flaws:

  • Every person must authorize every Server: onboarding means manually connecting one service after another
  • Security teams can't govern centrally: access depends on whatever each user happened to authorize at the time, with no central control or auditing
  • Work and personal accounts get conflated: there's no way to require corporate identity, so users can hook personal accounts into work tools

EMA makes the organization's IdP (identity provider) the authoritative decision-maker for MCP Server access. Admins define policy once, users sign in to the MCP host with their existing identity, and the IdP grants or denies access based on groups, roles, and conditional access rules.

The Core Mechanism: ID-JAG

EMA's underlying flow doesn't rely on per-server consent screens:

  1. When the user signs in via SSO, the client obtains an Identity Assertion JWT Authorization Grant (ID-JAG) from the IdP
  2. The client exchanges the ID-JAG for an access token with the MCP Server's authorization server
  3. The user is never redirected to a per-server consent page

Three properties follow:

  • Authorize once, inherited everywhere: when an admin enables a Server for the organization, users get it automatically, scoped to their existing groups/roles
  • Centralized policy and auditing: access decisions live in the IdP admin console, with a single audit trail across all connectors
  • No more personal/work account mixing: the interactive account-selection step is removed, lowering the risk of data accidentally flowing between personal and corporate accounts

Who Already Supports It

EMA's first wave of ecosystem support spans three sides:

Identity providers (IdPs)

  • Okta is the first supported IdP; organizations can provision MCP access to supported Servers via Okta's Cross App Access (XAA)

Clients

  • Anthropic has implemented EMA in its shared MCP layer; admins can authorize MCP Servers for users across Claude, Claude Code, and Cowork
  • Visual Studio Code supports EMA directly inside the IDE

Server side

  • Asana, Atlassian, Canva, Figma, Granola, Linear, and Supabase already support EMA
  • Slack and others are onboarding

How to Adopt It

If You're an Enterprise User

  1. Confirm IdP support (currently Okta, via the XAA protocol)
  2. Enable the target MCP Servers for your organization in the IdP admin console, scoped by group/role
  3. Users automatically get the authorized connectors the first time they sign in to Claude / Claude Code / VS Code — no per-server OAuth needed

If You're an MCP Server Developer

Implement EMA following the official specification:

  • Spec: Enterprise-Managed Authorization details the flows each party — client, server, authorization server — needs to implement
  • Source and spec: the ext-auth repository holds the latest spec and supporting material
  • Community: join the EMA Interest Group to discuss compatibility and iterate on the spec

When to Use EMA

ScenarioUse EMA?
Rolling out MCP to the entire companyYes — massively reduces onboarding friction
Need centralized security auditingYes — one audit trail in the IdP
Individual developer connecting a few Servers locallyNo — standard OAuth is fine
Enforcing corporate identity to prevent data leaksYes — removes interactive account selection

EMA doesn't replace standard MCP authorization; as an extension, it gives enterprise scenarios a "zero-touch" option. For small-to-mid-size teams and individual users, the existing per-user OAuth flow is unaffected.

Primary sources:

Related articles

Accio Work Enterprise: One-Click Team Sharing for Skills and Agents
AI Products

Accio Work Enterprise: One-Click Team Sharing for Skills and Agents

Alibaba's Accio Work launches its enterprise edition with one-click team sharing and auto-updates for Skills and Agents, solving a collaboration pain point for small and mid-size teams.

Toolin Editorial Team
Alipay Token Pay: Payment Infrastructure for Agents That Spend for You
AI Products

Alipay Token Pay: Payment Infrastructure for Agents That Spend for You

Alipay launches four products — the world's first Token Pay service, AI Wallet, AI Pay, and AI Collect — forming a full-stack AI-native payment system that has already completed 300 million agent payments.

Toolin Editorial Team
Hermes Agent: The Open-Source Python Project That Beat OpenAI Codex
AI Products

Hermes Agent: The Open-Source Python Project That Beat OpenAI Codex

Hermes Agent cut its startup time by 63% through three engineering optimizations and beat the Rust-written OpenAI Codex 6:5 across 11 CLI benchmarks, with GitHub stars passing 160,000.

Toolin Editorial Team
skill-cleaner: An Open-Source Tool to Put Your Agent Skills on a Diet
AI Tutorials

skill-cleaner: An Open-Source Tool to Put Your Agent Skills on a Diet

Peter, the 'father of the lobster,' has open-sourced skill-cleaner: 5 core features that audit and optimize your Agent skill descriptions, saving Token costs and improving Agent selection accuracy. Now open on GitHub.

Toolin Editorial Team
SkyClaw-v1.0: A Free Agent Model Closing In on Opus 4.6
AI Products

SkyClaw-v1.0: A Free Agent Model Closing In on Opus 4.6

Kunlun Tech releases the SkyClaw-v1.0 Agent model: performance approaching Claude Opus 4.6 at half the price of mainstream models, OpenAI-interface compatible, free for a limited time.

Toolin Editorial Team
CODA: Letting LLMs and Novices Write Speed-of-Light GPU Kernels
AI Products

CODA: Letting LLMs and Novices Write Speed-of-Light GPU Kernels

An open-source project from MIT, Princeton and others rewrites the scattered computations in Transformer training into the GEMM-Epilogue pattern, speeding up backpropagation by 1.6-1.8x

Toolin Editorial Team