Implementing Per-Call Authorization in MCP
ani_0523 · reddit · 2026-07-13
The author discusses the practical challenge of how to authorize every tool call after an MCP connection is established:
- MCP authentication alone only proves the client can connect to the server; by default, every tool can be invoked once connected.
- If a prompt injection occurs during an agent session, the model might directly invoke high-risk tools (like deleterepo).
- Their solution involves placing a lightweight proxy layer before the stdio path:
- Checking for grants before every tools/call.
- Allowing authorization to be revoked mid-agent run, causing the next call to fail immediately.
- Filtering tools/list so the model can't see unauthorized tools.
- Keeping secrets outside the agent process as much as possible.
They also open-sourced their implementation (Go, Apache-2.0) and asked the community whether they handle per-call authorization at the MCP layer or internally within the tool server.
Related event: Challenges of Tool-Level and Call-Level Authorization in Agent CLIs(2 posts)→
More from coding & agent
- A better path to agent autonomy is running waves, finding friction, and iterating — JnBrymn · 2026-07-22
- Coding agents are heading toward an AI-writes, AI-reviews, human-approves workflow — aftahi_ai · 2026-07-22
- oMLX 0.5.2 adds Mac menu-bar stats, low-bit decode kernels, and faster downloads — awnihannun · 2026-07-22
- GitHub review bot hits its PR limit and forces a 39-minute cooldown — DanielLockyer · 2026-07-22
- Max reasoning effort appears to be mobile-only in Codex Remote, not desktop — GabGarrett · 2026-07-22
- A Reddit demo argues online stores should expose carts and pricing through MCP — gelembjuk · 2026-07-22