Story · WorkOS
MCP: Scope step-up is not authentication step-up (WorkOS)
blog post · Story page
WorkOS separates widening what a token may do from confirming the person behind it is still present. MCP can express the first request and has no way yet to ask the second, so a step-up in scope tells you nothing about who's at the keyboard.
In plain words
- WorkOS says the Model Context Protocol can request wider permissions but cannot confirm that the user is still present.
- Wider permission changes what a digital access pass allows, while rechecking identity verifies who currently controls it.
- A request for broader access therefore does not prove that the original user remains at the keyboard.
- This gap matters to services that must know both what is allowed and who is currently requesting it.
Appeared in
- Anthropic's deliberately misaligned model, Fable 5.1, and a fix for reward hacking
Sep 02, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.