Analyze authentication and authorization requirements to identify security gaps
Separate authentication (who the caller is) from authorization (what they may do), spot where an agent or tool chain trusts the wrong party, and close the gap with identity propagation, scoped tokens, OAuth-compliant MCP servers, secrets kept out of prompts and deterministic enforcement.
Key points
- 1
Authentication establishes identity (SSO, OAuth login); authorization decides which records and actions that identity may touch. A system can have strong login and no authorization at all, which is the most common gap in the exam's scenarios.
- 2
Authorization belongs in deterministic code: tool handlers derive identity from the authenticated session and check ownership or role there. Never trust a user ID, role or claim that arrives through the model, a tool parameter or the conversation.
- 3
Avoid shared service accounts with broad rights. Have tools act on behalf of the user with delegated or on-behalf-of tokens so the downstream system enforces the user's own permissions; the agent should gain no authority the user lacks.
- 4
Scope tokens to the minimum access a role needs and prefer short-lived access tokens with refresh-token rotation; broad omnibus scopes widen the blast radius of any leak and muddy audit trails.
- 5
MCP over HTTP uses OAuth 2.1: the MCP server is a resource server, the client acts for the resource owner, discovery runs through Protected Resource Metadata and Authorization Server Metadata, PKCE is mandatory, and tokens go in the
Authorization: Bearerheader, never in query strings. - 6
MCP servers must validate that inbound tokens were issued for them (audience binding via the
resourceparameter) and must not pass a client's token through to upstream APIs; they obtain their own upstream token instead. Token passthrough breaks security controls, audit trails and trust boundaries. - 7
Confused deputy: an MCP proxy that uses a static client ID with a third-party authorization server and allows dynamic client registration must obtain per-client user consent before forwarding, otherwise a consent cookie lets an attacker's client obtain authorization codes silently.
- 8
Sessions are not authentication: MCP servers must verify every inbound request, use non-deterministic session IDs and bind sessions to the user identity.
- 9
Secrets never belong in prompts or committed config. Keep API keys and passwords behind tool handlers, and in Claude Code's
.mcp.jsonreference them as${VAR}from the environment; base64 encoding and "never reveal" instructions are not controls, and rotation alone leaves the secret in history. - 10
Claude Code and the MCP connector: remote servers authenticate with OAuth (
/mcplogin, per-user stored tokens;authorization_tokenon the connector), and the application is responsible for obtaining and refreshing tokens. - 11
Enterprise enforcement: managed settings (
managed-settings.json, MDM or server-managed) sit at the top of Claude Code's precedence order and cannot be overridden by user, project, local or--settings; deny rules beat allow rules from any file. ACLAUDE.mdinstruction is guidance, not enforcement. - 12
Agent SDK evaluation order is hooks, deny rules, ask rules, permission mode, allow rules, then
canUseTool. Calls auto-approved byacceptEdits,bypassPermissionsor an allow rule never reachcanUseTool, so authorization that must apply to every call belongs in aPreToolUsehook, whose deny holds in every mode. - 13
Everything the model outputs after reading untrusted content is untrusted: escape it before rendering, validate proposed actions against schemas and allowlists, and apply them with least-privilege credentials.
- 14
Distractors the exam likes: role banners in the system prompt, model-filled
user_idparameters, audit logging as a substitute for access control, longer-lived tokens for convenience, and a bigger model as an authorization mechanism.
Read the source
- MCP specification — Authorization
- MCP specification — Security best practices
- MCP connector (authentication)
- Claude Code — Connect to tools via MCP
- Claude Code — Settings files and precedence
- Agent SDK — Configure permissions
- Agent SDK — Control execution with hooks
- Mitigate jailbreaks and prompt injections
- Reduce prompt leak
Test yourself on Analyze authentication and authorization requirements to identify security gaps
Ten questions, with the answer and explanation after each one.