Story · arXiv
ACLE-MCP: Attested Capability Leases for Execution-Time Trust in Remote LLM Tool Use (arXiv)
paper · Story page
OAuth authorizes an MCP endpoint, but nothing proves which provider-side workload runs a later tool call once execution shifts, appraisal goes stale, or an undeclared downstream component appears. ACLE-MCP issues a short-lived, sender-constrained capability lease per protected call, a provider-side Execution Gate consumes it right before tool logic starts, and a runnable prototype uses Keycloak/OIDC and the MCP Python SDK.
In plain words
- Researchers created a system that checks the provider software handling each protected request just before it runs.
- Each request gets a short-lived digital permission naming the approved requester, provider software, action, limits, connected components, and required proof.
- The provider checks and uses up that permission immediately before its software performs the requested action.
- Organizations using remote artificial intelligence tools could better prevent approved requests from quietly reaching unapproved provider systems.
Appeared in
- GPT-6 Astra's score hinges on its harness, and agents rot geometrically with each step
Sep 04, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.