OWASP / OWASP/OWASP-MCP-Governance-and-Risk-Project
Add EMA references
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 86
- Forks
- 13
- PR merge metrics
- No merged PRs in 30d
Description
EMA/ID-JAGs allow centralized authorization, moves decision making from MCP users to company administrators, and gives some (albeit imperfect) centralized visibility. Worth a mention - and I'm happy to contribute if this would be a fit. I have been building POCs of this lately to prove it out, and some identity vendors like Okta have it in beta. So it's early but very promising and solves a number of real problems
https://blog.modelcontextprotocol.io/posts/enterprise-managed-auth/
Here's a walkthrough https://github.com/Zenable-io/labs/blob/main/labs/ema-mcp/README.md
I imagine a technical walkthrough isn't a fit for this project but I found a handful of places where it seems like at least a mention would be appropriate
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked EMA/ID-JAG blog post and walkthrough, then inspect the repository’s existing governance documentation for sections where centralized authorization or administrator decision-making belongs. Confirm the appropriate scope with maintainers before adding concise references, and consider the work done when the relevant sections link to accurate EMA material without expanding into a technical walkthrough.
Written by the indexing model from the issue text.
Assessment
- Domain
- authorization, documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100