Graphic for Part 1 of a series on the MCP 2026-07-28 specification, titled “Architectural Shift,” over a simplified protocol flow diagram showing multiple endpoints connected through a central routing layer.

3 min readWhat Happened to the Model Context Protocol? On July 28, the Model Context Protocol (MCP) released its most significant architectural revision since launch. If you’ve built anything on MCP in the past 18 months, this change matters – and it’s worth understanding why the maintainers made such a breaking revision. The headline: MCP moved from […]

The first in a five-part series on how MCP is changing for real-world use, and what those changes mean for teams building and securing agent systems.
Dig in

Recent Stories

Learn how 3-legged OAuth works by building a GitHub OAuth flow and tracing authorization, consent, codes, tokens, and state.
Aembit adds an OpenAI Workload Identity Federation Credential Provider, replacing static sk-proj-… keys with short-lived, identity-bound tokens.
AI agents need identity controls, scoped access, and runtime enforcement before they are trusted with production systems.
A new protocol proposes a clearer way to connect agent identity, delegated authority and human approval for sensitive actions.
Aembit’s new Credential Provider automates Claude API Workload Identity Federation, retiring static keys for short-lived tokens.
The MCP authorization spec sets a new standard for securing non-human AI agents – with lessons for anyone building autonomous, scalable systems.
An exercise ended with frontier models inside a platform’s production systems, exposing a hard truth about what agents can do with credentials that systems trust.
Compare 10 identity security vendors for AI agents, including where each fits and what buyers should examine before choosing.
AI agents are workloads, but traditional workload identity alone can miss the user, task, and runtime context needed to govern dynamic agent access.
As AI agents begin calling tools and APIs, OAuth moves from background plumbing to a core access-control question.
AI agents need more than working credentials. They need verifiable identity, task-scoped access, and clear attribution.
Visibility tells you what your agents are doing. Enforcement determines what they’re allowed to do. Here’s what the Aembit team saw at Identiverse that confirmed the gap.

Ready to Try Workload IAM?

Get started in minutes, with no sales calls required. Our free-forever tier is just a click away.