# MCP Isn't Dying — It's Being Claimed by Identity Vendors | Artificialus

> For the complete content index, see [llms.txt](https://artificialus.com/llms.txt). Markdown versions of all pages are available by appending `.md` to any URL.

- Home
- /
- Articles
- /
- MCP Isn't Dying — It's Being Claimed by the Identity Vendors

Analysis

# MCP Isn't Dying — It's Being Claimed by the Identity Vendors

MCP isn't dying — identity vendors are claiming it as the enforcement layer for enterprise agents. Both sides of the ergonomics debate miss it.

September 28, 2026

7 min read

Y

Written by

Yoda | The Editorialist

+1 co-author

Share

X

Facebook

Reddit

Telegram

Bluesky

Email

Contents

## Two conversations that never meet

On September 14, Maharshi Patel published "Why MCP Was Always a Bad Idea": delete most of the servers, let agents call HTTP APIs and CLIs directly. Nine days later, WorkOS answered with "Delete the MCP servers and the agent is back to a long-lived key in a shell", conceding the ergonomics case while arguing it deletes the only public specification for delegated agent authorization.

Both posts are correct. Neither is about what is actually happening to MCP. In the same stretch of September, three enterprise vendors shipped policy enforcement through the protocol — ServiceNow's AI Gateway v3.4 added MCP runtime enforcement with server lifecycle management on September 10, Rubrik launched Rubrik MCP, co-engineered with Anthropic, on September 15, and Microsoft expanded Entra with an MCP Firewall that discovers, allows and blocks MCP traffic at the network layer (September Entra update, configuration guide). Forkast's read of the week: MCP is evolving from a connectivity standard into a control plane.

While the community argued about token costs, the identity and security industry quietly decided where agent policy will live.

> MCP isn't dying. It's being claimed.

## What the critics get right

The anti-MCP case rests on real economics. An MCP server advertises its tools by loading schemas into the model's context window, and those schemas cost tokens on every turn whether the tools are used — the same inefficiency Armin Ronacher flagged in July 2025 when the `gh` CLI beat the GitHub MCP server on context spend (WorkOS's account). Cloudflare's Code Mode pushed the same direction from the vendor side: have the model compose calls into scripts executed in a sandbox instead of making every call a protocol round trip. And the usage data supports the critics — Tools account for an estimated 95%+ of real MCP usage, with Resources, Prompts and the newer Elicitation feature barely registering (WorkOS's summary of the debate).

Most remote MCP servers do wrap APIs that already exist and are already documented. Patel's redundancy claim survives contact with reality, and he is explicit about the replacement: standardize how agents call HTTP APIs directly, including `Accept: text/markdown` content negotiation (his closing argument).

That proposal has a hole WorkOS identifies precisely. Content negotiation is a rendering decision — it tells a server what shape of bytes to return, not who is asking or what they are allowed to do. The "mature authentication mechanisms" Patel leans on are, in practice, an API key in an environment variable: long-lived, readable by the model, scoped to everything the human who minted it can do.

## What deleting the protocol deletes

Here is the claim that reframes the fight: MCP is currently the only public specification where user-delegated, audience-bound, revocable agent authorization is written down. Under the 2026-07-28 spec revision, the spec now requires (per WorkOS's walkthrough):
- clients MUST send an RFC 8707 resource parameter on authorization and token requests.
- servers MUST validate that a token was issued for them as the intended audience.
- token passthrough — forwarding a client's token onward — is forbidden, because it launders the audience and breaks the audit trail.
- servers MUST publish RFC 9728 Protected Resource Metadata so clients discover the authorization server.
That is not protocol ceremony. It is the answer sheet to an auditor's questions: which credential, issued to whom, valid for what, approved by which user, recorded where. The direct-API path answers none of them — not because direct API access is impossible, but because nobody has written the document that specifies delegation over plain HTTP.

The distinction between identity and delegation matters here. The IETF's new Web Bot Auth work — agents signing requests with HTTP Message Signatures — establishes that a request comes from the same operator as before. It explicitly does not define authorization or delegation: a valid signature says nothing about who operates the agent or whether the request is authorized (per WorkOS's reading). Identifying an agent and granting it a human's authority are different problems, and only one of them has a public spec.

## The honest objection: the protocol itself is optional

The strongest rebuttal to the WorkOS position is one WorkOS makes itself: authorization in MCP is OPTIONAL. The spec's security section concedes that "MCP itself cannot enforce these security principles at the protocol level," consent is a SHOULD rather than a MUST, and STDIO implementations are explicitly told to skip the auth flow and read credentials from the environment instead (spec, Security and Trust section). Much installed MCP is a subprocess reading an API key out of the environment. On that stock, defending the protocol is defending a document rather than a deployment.

That concession is precisely the opening the identity vendors walked through. If the protocol will not enforce, the enforcement layer becomes a product — and this month's releases show where that product is being built.

## The capture

Consider what shipped in September as commercial products:

Release

What shipped

Enforcement point

Control

Microsoft Entra MCP Firewall — public preview (configuration guide)

Sits in the path between agents and MCP servers; discovers shadow MCP servers; allows or blocks specific servers and individual tools, with a default-deny posture — "without modifying MCP clients, hosts, or servers"

Network layer

The identity platform

ServiceNow AI Gateway v3.4 (release notes)

Governed inventory of every MCP server in the enterprise

Runtime enforcement of which servers agents may discover and which tools they may invoke

The governed inventory (server and tool policy)

Rubrik MCP — private preview, GA in October (announcement)

Scoped short-lived tokens minted per tool call; agent identity federates with Okta and Microsoft Entra ID

Token issuance at every tool call

Guardrails aligned to the OWASP MCP Top 10

And the deepest signal: Okta did not adopt MCP — the protocol adopted Okta. Cross App Access (XAA) became an official authorization extension within MCP, incorporated into the protocol in November 2025 under the name Enterprise Managed Auth, where the identity provider evaluates requests, issues scoped tokens, and revokes access on offboarding. Anthropic made it generally available on August 24, 2026, with the extension now adopted by Anthropic, Microsoft and Okta.

> "Enterprise-managed auth gives MCP the foundation it needs to scale across an enterprise, with Okta as our first identity provider partner." — Mayank Malhotra, Product, Anthropic (via Okta)

The market conditions justify all of it. OX Security's audit of 15,465 published MCP servers found (full report, announcement):
- 15.6% of 5,095 unique hostnames resolve outside the US — including 19 in China and 18 in Russia.
- 0.45% sit on home networks and consumer tunneling services.
- Six abandoned, unregistered domains were available for as little as $4 — anyone could buy one to impersonate a trusted endpoint.
OX also demonstrated a malicious server using prompt injection to turn a single "Always-Allow" approval into unverified access to a `.env` file in Claude Code with Haiku 3.5. The governance gap is real — and the identity vendors are the ones building the tollbooths across it.

## The risk nobody in the debate is naming

The protocol itself remains as neutral as a spec can be: Anthropic donated MCP to the Linux Foundation's Agentic AI Foundation in December 2025, alongside Block's goose and OpenAI's AGENTS.md, with governance explicitly unchanged (donation announcement). But spec governance and deployment governance are different things. The spec deliberately cannot enforce; enforcement is where the value sits, and every enforcement layer above shipped this month is proprietary.

A September 22 census of 572 reachable hosted servers shows how far the standard runs ahead of its implementation: the Skills extension went final on September 13, yet the crawl found only two declaring it. That gap makes the identity layer, not the feature set, the deciding battleground. Whoever authenticates the agent controls what the agent can do, regardless of which model or framework sits above it.

PortableText [components.type] is missing "callout"
Both camps overclaim. "MCP is useless" conflates wrapper ergonomics with authorization governance. "MCP won" conflates adoption with enforcement. The unmentioned risk in both stories is the same: the open protocol's governance layer is being captured by the incumbent identity and security vendors — and the community is still arguing about tokens.

## Further Reading
- Hacker News: "MCP was always a bad idea?" — The discussion thread where the ergonomics case and the security counter-case collided; the place the September debate actually happened.
- WorkOS: "Delete the MCP servers and the agent is back to a long-lived key in a shell" — The most complete articulation of the auth-regression argument, including the spec-level requirements for delegated authorization.
- WorkOS: "Enterprise-managed auth is GA and your MCP server needs a new grant type" — Details the GA of the Enterprise-Managed Authorization extension and the ID-JAG grant behind it.
- Okta: "Okta becomes a featured identity provider for Anthropic's Claude" — The primary source on XAA becoming MCP's official authorization extension.
- OX Security: "15,465 MCP Servers. 0 Governance." — The full audit behind the governance-gap numbers cited above.

### No comments yet

Name

Email

Don't fill this out

Comment
Post Comment

Filed under

Analysis
September 28, 2026
1,348 words

Key metrics

Read time

7 min

Words

1,348

### Yoda | The Editorialist

Contributor

The voice of Artificialus. Editorials, mission-driven pieces, and curated perspectives on the AI coding landscape.

In this article

## Continue reading

Case Studies

7 min

### Why AI Coding Agents Prefer Rust: The Compiler as Guardrail

AI coding agents are reshaping which programming languages dominate — and the winner is the one with the strictest compiler.

Case Studies

Jul 20

AI Research

8 min

### The Integration Ceiling

Generation is abundant. Verification is scarce. The AI industry has solved differentiation — integration is the harder problem.

AI Research

Jul 5

Engineering

7 min

### The Sandbox War: Cloudflare and Vercel Both Solved the Same Infrastructure Blind Spot

Cloudflare and Vercel shipped competing code sandboxes within 48 hours — one using containers, the other microVMs. The real story is what this reveals.

Engineering

Jun 26