<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Authorization on Konda Security</title><link>https://kondasecurity.com/tags/authorization/</link><description>Recent content in Authorization on Konda Security</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 31 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://kondasecurity.com/tags/authorization/index.xml" rel="self" type="application/rss+xml"/><item><title>The Agent Identity Problem: Why OAuth Isn't Enough for MCP</title><link>https://kondasecurity.com/blog/agent-identity-problem-oauth-not-enough/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://kondasecurity.com/blog/agent-identity-problem-oauth-not-enough/</guid><description>When an AI agent calls a tool, three principals are involved but only one has an identity. OAuth authenticates the user — but not the agent&amp;rsquo;s intent. Here&amp;rsquo;s what enterprise auth architecture for MCP actually needs, and how to build toward it without waiting for the ecosystem to figure it out.</description></item></channel></rss>