Session
A Stable URL Is Not A Credential: Building OAuth-Native MCP Servers
MCP servers need stable addresses that teams can bookmark, share in docs, and paste into agent configs — but stable URLs must not double as access credentials. This talk walks through building an MCP server where the URL is a resource address and credentials live in OAuth, PKCE, and human-approved grants. Using a production self-hosted MCP registry as the case study, we cover: Protected Resource Metadata for scope advertisement, Dynamic Client Registration for automatic agent enrollment, why token-in-URL sharing breaks down at team scale, how operators narrow requested scopes during grant review, and how connection revocation works without changing the URL. The audience will leave with concrete patterns for separating resource addressing from credential management in their own MCP servers.
Shub Argha
Head of Forward Deployed Engineering @ Arcade.dev
New York City, New York, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top