The problem
An existing application needed controlled access for MCP tools: explicit consent, limited scope, and a way to take access back.
What I did
- Consent flows and scoped grants for tool access.
- Refresh-token rotation, reuse handling, revocation and authorization checks at execution.
- A desktop bridge, with regression-test coverage.
Decisions
Check at execution
Access is checked again when a tool actually runs, not only when it is granted.
Rotate refresh tokens and detect reuse
With a clear path to revoke access.
Specify first
Written specifications and regression scenarios guide review of agent-assisted implementation.
Boundaries
My role: specifications, design direction and review of agent-assisted implementation. The underlying application was inherited. A development prototype, not deployed; planned tools are not presented as finished.