OpenAI's Sign in with ChatGPT lets Plus and Pro users run an app's AI requests on their own plan, up to a weekly cap they set per app. That cap reserves none of the user's quota, so builders still need their own API key for any request the plan cannot cover.
Reality
- Evidence55
- Adoption30
- Hype gap+5
- Incentives30
- Confidence50
MCP Python SDK maintainers fixed a flaw rated up to 7.5 that lets malicious servers steal OAuth client secrets, in versions 1.30.0 and 2.2.0. Two of the affected providers stay exposed after upgrading until the calling code passes issuer=.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence70
QRFLOW.codes' developer refused both fixes a security report proposed for open OAuth client registration, saying either would lock Claude and ChatGPT out. The exposure turned out to be a consent screen showing attacker-chosen app names, now handled by trusting redirect hosts.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives50
- Confidence50
MCP servers that skip audience binding accept tokens minted for other servers, says a dev.to OAuth 2.1 guide that puts it in the 80% most guides skip. The check depends on RFC 9728 metadata the server publishes and a resource parameter the client sends.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence35
The MCP spec mandates OAuth 2.1 with PKCE, dynamic client registration and metadata discovery for remote servers. The one-hour tokens and customer-facing audit logs procurement asks about come from a guide's own bar.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence48
IFTTT's authorization redirect arrives with no code_challenge, and an authorization server that mandates PKCE answers invalid_request. Publora's developer kept the requirement and put a Cloudflare Worker in front of it.
Reality
- Evidence60
- Adoption20
- Hype gap−5
- Incentives55
- Confidence55
The auth overhaul in the final MCP spec reaches only remote transports, which turns a compliance question into a question about deployment topology, and even the vendors credited with getting ahead of it need checking.
Reality
- Evidence38
- Adoption45
- Hype gap+28
- Incentives55
- Confidence45
The tool logic is one route handler. The other five routes stand up an OAuth authorization server and two well-known documents, and the 401 that points at them decides whether Claude ever shows a sign-in page.
Reality
- Evidence52
- Adoption25
- Hype gap+8
- Incentives55
- Confidence58
Self-hosted Kubernetes still hands out certificate files that keep working after their owner leaves. The fix in a CNCF walkthrough turns on one Keycloak toggle, because a confidential client only moves the shared static credential onto every laptop.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+12
- Incentives45
- Confidence58
One authentik CVE covers a token endpoint accepting a missing code_verifier; another, six months later, covers an authorization endpoint accepting a missing code_challenge. OpenAM's equivalent check ships switched off.
Reality
- Evidence60
- Adoption45
- Hype gap+15
- Incentives20
- Confidence55
The S256 pin is a per-client attribute, and the executor that builds a client from a published metadata document sets three attributes, all unrelated to PKCE. The executor addition imports cleanly, yet it never runs.
Reality
- Evidence58
- Adoption12
- Hype gap−12
- Incentives22
- Confidence52
An MCP server for social publishing shipped OAuth, sixteen tools and six destructive flags. The failures that actually hurt still come back as ordinary successes.
Reality
- Evidence42
- Adoption16
- Hype gap+8
- Incentives72
- Confidence55
A New Stack prescription lists six identity capabilities for autonomous agents. The useful part is which old assumption each one retires, and what per-step credentials cost to run.
Reality
- Evidence28
- Adoption
- Insufficient
- Hype gap+42
- Incentives58
- Confidence46
MongoDB's OAuth 2.1 platform issues tokens that call the Atlas Administration API with the authorizing user's full permissions. Least-privilege role design stops being hygiene and becomes the control.
Publishers:mongodb.com
Reality
- Evidence76
- Adoption15
- Hype gap−5
- Incentives62
- Confidence63
A dev.to writeup documents Amazon Cognito killing a spec-compliant MCP connector at the first redirect, and the only fix on offer is a proxy that strips one parameter and nothing else.
Reality
- Evidence46
- Adoption18
- Hype gap−6
- Incentives30
- Confidence44