September 2026 Summaries
1 posts from PropelAuth
Filter
Month:
Year:
Post Summaries
Back to Blog
PropelAuth has introduced a Default Resource setting for MCP Authentication to support OAuth 2.0 clients such as Microsoft Copilot Studio that do not send the resource parameter required by the MCP authorization specification. When enabled, the setting substitutes a configured MCP server URL for missing resource values, allowing authorization to proceed while keeping issued tokens audience-bound to that specific server; clients that supply a resource parameter continue to work unchanged. The feature is intended only for environments with one MCP server and should remain disabled when all clients are MCP-compliant or when multiple servers share an authorization environment, since selecting a default resource would be ambiguous. The change addresses a practical compatibility gap between generic OAuth 2.0 integrations and MCP’s OAuth 2.1-based authorization requirements, particularly RFC 8707 resource indicators, which protect against tokens being used with unintended servers. Administrators can enable the option in PropelAuth’s dashboard, configure the server’s canonical URL, and retain existing protections such as PKCE, scope consent, redirect URI controls, and token introspection.
Sep 04, 2026
1,243 words in the original blog post.