Per-Tool OAuth Scopes for MCP, Derived from Your Schema
Blog post from Wundergraph
In this detailed exploration, Ahmet Soormally discusses the importance of implementing per-tool OAuth scope enforcement for MCP (Managed Cloud Platform) servers to ensure AI agents do not receive excessive permissions, thereby maintaining the principle of least privilege. The article explains how the Cosmo Router now leverages @requiresScopes directives in federated GraphQL schemas to enforce field-level authorization, avoiding the need for additional authorization layers. By dynamically computing scope challenges when scopes are insufficient, this approach allows agents to step up authorization within the same session without human intervention, thus enhancing security and operational efficiency. The implementation integrates seamlessly with existing identity providers and emphasizes the avoidance of creating separate backends for agents, which often lead to policy drift and increased audit requirements. Soormally highlights the router's capability to resolve authorization issues autonomously, ensuring that AI agents are granted only the necessary permissions, thereby preventing over-privileging and maintaining a unified security model across different consumer types.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 67 | 6,108 | 613 | 170 | +36% |
| AI Agents | 5 | 4,430 | 1,100 | 236 | -3% |
| Observability | 4 | 4,496 | 812 | 176 | +40% |
| Platform Engineering | 4 | 1,080 | 232 | 64 | +125% |
| Developer Experience | 1 | 611 | 275 | 100 | +27% |
| LLM | 1 | 5,932 | 1,046 | 223 | -2% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.