

MCP Server Auth: Scopes, Step-Up Flows, and Token Exchange
βπ MCP Server Auth: Scopes, Step-Up Flows, and Token Exchange
βYou've got OAuth working on your MCP server. Great.
βNow comes the question: is it actually ready for production?
βMost MCP auth tutorials stop at the happy path: token in, tool runs, you're done.
βBut once you have real users, multiple tools with different permission levels, or a security review, that default implementation starts to show its cracks.
βIn this live, hands-on session, we'll take a working OAuth-protected Apollo MCP Server and show you exactly what needs to change before you ship.
βπ οΈ You'll learn how to:
βDefend against confused-deputy attacks with practical configuration changes
βConfigure per-tool scopes so different tools require different permissions
βImplement step-up authorization flows when users cross permission boundaries
βBuild the token exchange pattern using Apollo Router extensibility
βWe'll demonstrate the attacks, explain why they work, and implement the fixes live.
βπ» Who should attend?
βThis session is for developers who have already configured OAuth on an MCP server and want to harden it for production.
βPrerequisite: Getting Started with MCP Server Auth (July 8) or equivalent experience setting up OAuth on an MCP server.
βBring the laptop you'd use to deploy the real thing, we'll be building along together.
βπ€ Speaker
βCamille Lawrence, Sr. Software Engineer, Apollo GraphQL
βπ July 22 | 9:00 AM PT
βπ [ Register here ]
βWe look forward to seeing you there!