· Amit Kothari
· Engineering
Who let the agent in, what can it touch, and whose name is on it: the three auth questions for enterprise MCP
Enterprise-managed authorization (EMA) for MCP went stable on June 18, 2026, and got called the missing auth layer for AI agents. It answers one question well: who let the agent in. Two more stay open, what the agent can touch and whose name is on it. Here is why all three matter.