Session

A Stable URL Is Not A Credential: Building OAuth-Native MCP Servers

MCP servers need stable addresses that teams can bookmark, share in docs, and paste into agent configs — but stable URLs must not double as access credentials. This talk walks through building an MCP server where the URL is a resource address and credentials live in OAuth, PKCE, and human-approved grants. Using a production self-hosted MCP registry as the case study, we cover: Protected Resource Metadata for scope advertisement, Dynamic Client Registration for automatic agent enrollment, why token-in-URL sharing breaks down at team scale, how operators narrow requested scopes during grant review, and how connection revocation works without changing the URL. The audience will leave with concrete patterns for separating resource addressing from credential management in their own MCP servers.

Shub Argha

Head of Forward Deployed Engineering @ Arcade.dev

New York City, New York, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top