coder / coder/registry

Agent Identity and Delegated Authority Across MCP Servers

Open
#1,087 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
HCL
Stars
79
Forks
161
Avg merge
1d 10h
Merged PRs (30d)
38

Description

As AI agents increasingly use MCP servers to access tools, data, and external services, it may become difficult for users to understand and control the authority delegated to those agents.

For example, if an agent is authorized to perform an action through an MCP server, how can the user clearly determine:

* Which agent is actually acting?
* On whose behalf is it acting?
* What permissions were originally granted?
* What actions is the agent currently authorized to perform?
* Can those permissions be delegated to another agent or MCP server?
* Can the user trace the chain of authorization when multiple agents are involved?
* How can the user revoke or limit that authority consistently across different agents and MCP servers?

This becomes more important as users begin working with multiple agents from different providers and allow them to interact with increasingly sensitive tools and services.

I would be interested to know whether this is already considered a problem within the MCP ecosystem, and how others are currently addressing it.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.