MCP's two-year shift: the default caller moves from a human at a screen to a cloud-side process
从屏幕前的人到云端的进程:MCP 默认调用者的两年转向
MCP maintainers published a new roadmap on Aug 22, listing agent identity as one of five priorities. The shift moves authorization away from a human clicking approve in a browser and toward cloud agents that carry their own identity and obtain tokens autonomously. The path started with OAuth 2.1 in March 2025, added machine-to-machine credentials in November 2025, and introduced the Workload Identity Federation proposal WIF in December 2025. The cost: the July 2026 spec removed session headers, mandated self-contained requests, and deprecated the recently added Sampling and Roots capabilities. The chokepoint moves from personal API keys to the cloud platform and enterprise IdP that issue tokens. WIF and DPoP are still drafts; ID-JAG remains an IETF draft. The HN thread scored 269 points, with over-engineering criticism taking up a fair share of the discussion.
Why it matters: MCP roadmap elevating agent identity to a priority is a key signal of the protocol's shift from local scripts to unattended cloud workloads. The article traces the two-year evolution with concrete dates and changelog references — good information density. Deduction: this is a ...