

What's up with MCP? Live by Scalekit x Okta x MCPJam
Somewhere right now, an IT admin is looking at an MCP server that 2000 employees want to use, and doing the math on per-user consent screens at that scale. Who approved which connection? What happens the day someone leaves? Per-user OAuth was never built to answer that — and the ecosystem just shipped its answer.
The solution: Okta calls it Cross-App Access. The MCP spec calls it Enterprise-Managed Auth. Different docs, different names, same mechanism underneath. By supporting that one exchange: you're compatible with both. It's also how your server ends up in the connector catalogs enterprise admins actually pick from.
Then there's July 28, when the next spec version ships. The protocol core goes stateless, and MCP gets a formal deprecation policy.
The hard part of all of this: auth doesn't fail loudly. A wrong decision in this implementation hands out a token. So, the minds and hands behind MCP at Scalekit, Okta, and MCPJam are coming together to talk about it.
This is for you, if you’ve:
Built an MCP server for a B2B product: Customers (or their security teams) have started asking questions you don't have clean answers to.
Own the authorization server: Whether you built it or you're the platform engineer who inherited it.
Deciding right now whether enterprise-readiness is worth the work: A founder or tech lead sizing up XAA/EMA before committing engineering time.
Core takeaway: Everyone who registers gets the recording and the XAA Production Readiness Guide.