Project 07 of 13

MCP Tool Access & Authorization

How a tool gets access, uses it — and loses it.

  • Ongoing
  • Prototype
  • Not deployed
Read the case study

The problem

An existing application needed controlled access for MCP tools: explicit consent, limited scope, and a way to take access back.

What I did

  • Consent flows and scoped grants for tool access.
  • Refresh-token rotation, reuse handling, revocation and authorization checks at execution.
  • A desktop bridge, with regression-test coverage.

Decisions

  1. Check at execution

    Access is checked again when a tool actually runs, not only when it is granted.

  2. Rotate refresh tokens and detect reuse

    With a clear path to revoke access.

  3. Specify first

    Written specifications and regression scenarios guide review of agent-assisted implementation.

Boundaries

My role: specifications, design direction and review of agent-assisted implementation. The underlying application was inherited. A development prototype, not deployed; planned tools are not presented as finished.

Synthetic demo · fictional data