Home / Companies / Descope / Blog / Post Details
Content Deep Dive

XAA vs. ID-JAG vs. EMA: What's the Difference?

Blog post from Descope

Post Details
Company
Date Published
Author
Alex Brown
Word Count
2,690
Company Posts That Month
2
Language
English
Hacker News Points
-
Post removed?
No
Summary

Cross-App Access (XAA) is an identity pattern in which an enterprise identity provider brokers one application’s access to another application’s API or MCP server on a user’s behalf, replacing separate API keys or individual consent flows while leaving final authorization decisions to the resource application. ID-JAG, or Identity Assertion JWT Authorization Grant, is the IETF standards-track draft that defines the associated token exchange: a requesting application trades a user identity token for a short-lived, signed assertion targeted to a specific resource authorization server, which validates it and issues its own access token. Enterprise-Managed Authorization (EMA) is a stable, opt-in Model Context Protocol extension that applies XAA and ID-JAG to let administrators preauthorize MCP clients to connect to MCP servers for their users. Although the terms are often used together, XAA describes the broad access pattern, ID-JAG describes the technical grant and assertion, and EMA describes the MCP-specific administrative capability. EMA governs whether a connection is permitted and at which scopes when the token is issued, while ongoing controls over an agent’s actions remain the responsibility of the resource server through its access-token policies and per-tool or per-scope enforcement.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 42 No monthly metrics for this publish month.
Platform Engineering 10 No monthly metrics for this publish month.
AI Agents 4 No monthly metrics for this publish month.
LLM 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.