MCP's biggest enterprise blocker is gone: zero-touch OAuth for MCP servers is now stable. The standard model required every employee to authorize every MCP server individually - a deal-breaker for IT and security teams. Enterprise-Managed Authorization flips this: admins define policy once through their IdP (Okta is first), and users get all authorized servers on first login, scoped to their roles. Already live in Claude, VS Code, and 7 servers including Figma, Linear, and Supabase. Security teams now have a centralized audit trail across every MCP connection.
https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/
Post #1274
217