Study notes · 2.4% of the exam

Analyze authentication and authorization requirements to identify security gaps

Separate authentication (who the caller is) from authorization (what they may do), spot where an agent or tool chain trusts the wrong party, and close the gap with identity propagation, scoped tokens, OAuth-compliant MCP servers, secrets kept out of prompts and deterministic enforcement.

Key points

  1. 1

    Authentication establishes identity (SSO, OAuth login); authorization decides which records and actions that identity may touch. A system can have strong login and no authorization at all, which is the most common gap in the exam's scenarios.

  2. 2

    Authorization belongs in deterministic code: tool handlers derive identity from the authenticated session and check ownership or role there. Never trust a user ID, role or claim that arrives through the model, a tool parameter or the conversation.

  3. 3

    Avoid shared service accounts with broad rights. Have tools act on behalf of the user with delegated or on-behalf-of tokens so the downstream system enforces the user's own permissions; the agent should gain no authority the user lacks.

  4. 4

    Scope tokens to the minimum access a role needs and prefer short-lived access tokens with refresh-token rotation; broad omnibus scopes widen the blast radius of any leak and muddy audit trails.

  5. 5

    MCP over HTTP uses OAuth 2.1: the MCP server is a resource server, the client acts for the resource owner, discovery runs through Protected Resource Metadata and Authorization Server Metadata, PKCE is mandatory, and tokens go in the Authorization: Bearer header, never in query strings.

  6. 6

    MCP servers must validate that inbound tokens were issued for them (audience binding via the resource parameter) and must not pass a client's token through to upstream APIs; they obtain their own upstream token instead. Token passthrough breaks security controls, audit trails and trust boundaries.

  7. 7

    Confused deputy: an MCP proxy that uses a static client ID with a third-party authorization server and allows dynamic client registration must obtain per-client user consent before forwarding, otherwise a consent cookie lets an attacker's client obtain authorization codes silently.

  8. 8

    Sessions are not authentication: MCP servers must verify every inbound request, use non-deterministic session IDs and bind sessions to the user identity.

  9. 9

    Secrets never belong in prompts or committed config. Keep API keys and passwords behind tool handlers, and in Claude Code's .mcp.json reference them as ${VAR} from the environment; base64 encoding and "never reveal" instructions are not controls, and rotation alone leaves the secret in history.

  10. 10

    Claude Code and the MCP connector: remote servers authenticate with OAuth (/mcp login, per-user stored tokens; authorization_token on the connector), and the application is responsible for obtaining and refreshing tokens.

  11. 11

    Enterprise enforcement: managed settings (managed-settings.json, MDM or server-managed) sit at the top of Claude Code's precedence order and cannot be overridden by user, project, local or --settings; deny rules beat allow rules from any file. A CLAUDE.md instruction is guidance, not enforcement.

  12. 12

    Agent SDK evaluation order is hooks, deny rules, ask rules, permission mode, allow rules, then canUseTool. Calls auto-approved by acceptEdits, bypassPermissions or an allow rule never reach canUseTool, so authorization that must apply to every call belongs in a PreToolUse hook, whose deny holds in every mode.

  13. 13

    Everything the model outputs after reading untrusted content is untrusted: escape it before rendering, validate proposed actions against schemas and allowlists, and apply them with least-privilege credentials.

  14. 14

    Distractors the exam likes: role banners in the system prompt, model-filled user_id parameters, audit logging as a substitute for access control, longer-lived tokens for convenience, and a bigger model as an authorization mechanism.

Test yourself on Analyze authentication and authorization requirements to identify security gaps

Ten questions, with the answer and explanation after each one.