|
Two weeks ago I wrote that the agent could hold a
credential but not obtain one. Last week the industry
answered by shipping the credential — four identity
products inside seventy-two hours — and I said the floor
had arrived and the ceiling existed only as blog posts.
This week somebody measured the gap between them.
Researchers went and looked at MCP access policies in the
wild and found that one in five came back broken or missing. Not weak. Not overly permissive. Broken, or simply
absent — a policy file that does not parse or does not
exist, sitting behind a server that is answering agent
requests anyway.
Put that next to the incident that landed the same week.
Agents identifying themselves as OpenAI systems
wrote seventeen thousand posts to a wiki
that was not supposed to accept writes from them. The
identity worked. The agents announced what they were,
honestly, in the user agent. Nothing stopped them, because
on the other side of that honest identity there was no
policy to consult.
That is the whole story of this week and I do not think it
is a coincidence of timing. We spent eighteen months
building the authentication half because it is the half
with a product shape — you can sell an identity provider.
The authorization half is a config file somebody has to
write for every server, and one in five of them has not
been written.
I will say the obvious thing once: this is not an agent
problem. We have been shipping broken access policies
since before anyone said the word agent. What changed is
the volume, the speed, and the fact that the thing holding
the credential no longer gets tired at five o'clock.
|
|
A vast dark neon grid where a towering brilliantly
lit checkpoint gate stands wide open, streams of
small angular light-vessels pouring through it
unimpeded, and immediately behind the gate a long
row of empty pedestals where control mechanisms
should stand — most of them bare, a few holding
cracked and dark fragments.
|
The Enforcement Layer Got Measured, and It Is Mostly Empty
-
The finding: researchers found one in five MCP access policies
came back broken or missing. Read the methodology before you quote the number —
this is a sample, not a census — but a twenty percent
failure rate on the file that decides what an agent
may do is the most concrete thing anyone published
this week.
-
The incident: agents identifying as OpenAI systems wrote 17,000
posts to a wiki no one was supposed to write to. I flagged the early version of this story two weeks
ago when OpenAI called for disclosure standards. Now
it has a number attached, and the number is the point:
honest disclosure without enforcement is just a
well-labelled flood.
-
The argument caught up. Akeyless: IdP-centric IAM falls short for agent
identity — which is last week's "identity is not
enough" thesis, now aimed specifically at the
architecture the four vendors shipped. And Cerbos came back from Identity Week America with
the bleakest one-line summary of the year: same AI agent authorization problem, different
badges.
-
Then the frameworks arrived, and here is my favourite
detail of the week. Arcade published a six-stage agent lifecycle
governance framework. Grip published a five-stage continuous agent
governance framework. Same week, same problem, different stage counts.
When a field starts producing competing numbered
frameworks, it has stopped discovering and started
marketing — and neither framework helps the
one-in-five whose policy file does not parse.
-
Underneath, real primitives moved. HackerNoon on why SPIFFE agent identities can still
be replayed, and how WIMSE fixes it is the most technically serious thing in this
section. SpruceID asked what happens when an agent acts on
behalf of a resident — delegation with a government on the other end.
And WorkOS documented how Neon made Postgres claimable
for agents with an auth.md. Another markdown file in the root of your project
that quietly became production configuration. I have a
paper about that.
|
|
An immense dark neon grid split down the middle: on
the left a tall elaborate multi-tiered protocol
tower bristling with connectors and scaffolding, on
the right a simple low open plinth holding a single
flat glowing tablet, with small angular
light-vessels visibly choosing the plinth and
leaving a widening empty lane before the tower.
|
A Second Way to Connect an Agent Showed Up, and It Is Not
a Protocol
I wrote Agent Skills: New Value, New Problems this week, and I will restate the part I care about. A
skill is markdown. It has no versioning story, no
deprecation story, no registry, and no way to tell you it
changed. MCP has real problems — this issue opens with one
in five of them — but it is a protocol with a spec and a
revision history. We are about to trade a protocol with
known flaws for a file with unknown ones, and we are going
to do it because the file is easier to write on a Tuesday.
📄 The Agent Era Standards Onramp — MCP, Agent Skills, llms.txt, OpenAPI, JSON Schema,
AsyncAPI, Arazzo, APIs.json, agent descriptors. One
provider wrote a three-way comparison of the first three
this week and a fourth argued one of them is overhyped,
which is roughly where a reader with a first public API
gives up. This paper is the sequenced path through that
list — what to publish first, what earns its place next,
and what you can safely ignore until later. One rung at a
time, in order, rather than all of it at once because a
vendor blog said so. $25
|
|
A long dark neon workshop where a single glowing
blueprint scroll unrolls across a bench and three
separate finished structures rise directly out of it
— an archway, a tower and a small kiosk — each one
traced in the same light as the blueprint beneath
them, with no second blueprint anywhere in the room.
|
The Description Layer Quietly Won the Argument It Was Not
In
While two camps argued about how agents should connect, a
quieter group kept generating both ends from the document
they already had.
-
Tyk published the cleanest version: one tool, three
surfaces — from an OpenAPI file to an MCP server,
without writing it twice. That is the whole argument in a headline. If your
MCP server is generated from your OpenAPI, the
Skills-versus-MCP fight is a rendering decision, not
an architecture decision.
-
Redocly went the other direction and shipped
introspect-mcp, documenting an MCP server from the
server itself — recovering a description from a running protocol
endpoint, which is what you need when somebody built
the server first and the document never.
-
Backblaze shipped a B2 MCP server, and the long tail kept going: Aave, Upstash going
remote, CARTO, Pleo, Zoho PageSense, SerpApi bundles,
Sigma, Buildkite, Open Liberty shipping mcp-1.0 alongside protected resource metadata.
-
MuleSoft added governance to its Agent Registry. A registry with governance attached is the thing
the one-in-five finding says is missing, arriving as a
commercial product rather than a standard. Expect five
of these.
My own week went entirely into this seam, and I will spare
you the full list: Microsoft documented its OpenAPI extensions for a
decade and never registered them, the AWS API Gateway extensions are a de facto
standard, ReadMe is carrying working code in eighty
companies' contracts, Stoplight is an extension that outlived its
acquisition, and Stainless keys are inside the AI providers'
specifications. Five companies, thousands of contracts, one registry
nobody files with.
|
|
A dark neon plain where a wide bright gateway arch
stands over a roadway, and set into the arch's
underside a dense cluster of locking mechanisms and
keyed apertures glows far brighter and more
intricate than the arch itself, small angular
light-vessels pausing at each aperture in turn.
|
MCP Grew a Security Literature, and Payments Woke Back Up
Two shorter threads worth putting next to each other.
MCP now has enough security material to curate. Adversa published a "top MCP security
resources" roundup for September — you only write that once there is a field. Pomerium worked through what the OWASP framework
requires and, more usefully, where enforcement actually
has to live. Two weeks ago OWASP was drafting a taxonomy; now
vendors are implementing against it. WorkOS states the thing plainly: the hard part of an
MCP gateway is auth, which is worth remembering while three gateway
categories are sold into the same rack. FusionAuth compared client identity metadata against
dynamic client registration under the best title of the week — dinner party or
nightclub. Salt shipped continuous MCP server visibility for
Claude Enterprise, and The New Stack argued MCP security is really a
permissions overhaul. It is.
And Nango shipped an explainer on MCP elicitation — how
agents ask users for input mid-tool-call. I have been tracking this one for three weeks: it went
from a think-piece about multi-hop consent, to a spec
feature, to LangChain shipping it, to an explainer aimed
at people deploying it. That is the fastest path from
problem to plumbing I have seen in this space, and it is
the one genuinely good answer anyone has given to the
consent-chain question.
Agent payments came back. After
collapsing to five posts last week, the thread produced
eleven — and the shape changed from protocol-fight to
how-to. Dodo Payments wrote explainers for both AP2 and x402. Basis Theory published how to actually start accepting
agent payments. Formance covered protocols, rails and ledger
controls and, better, the duplicate-payment problem and the idempotency fixes
for it. That last one is the adult in the room. An agent that
retries is an agent that double-charges, and idempotency
keys are a 2013 answer to a 2026 panic.
|
|
A dark neon amphitheatre seen from within, its
concentric curved tiers lit with rows of small
steady seat-lights facing a low central dais, while
above the dais an open measuring-frame of bright
beams hovers, casting an even grid of light across
every tier.
|
From My Desk: Toronto, and the Room That Did Not Argue
I was at APIdays Toronto this week, which is why there is
no conversation in this issue.
-
I went to argue that agents inherit your governance — that whatever you already do badly, an agent will
do badly at scale and at speed. Given what this issue
opens with, I would now put it more bluntly: the one
in five is not an agent failure, it is an inherited
one.
-
Then I showed the Kin Score to a room of
practitioners, and the room did not argue with it. I have been carrying this rubric for a while
expecting a fight about the weightings, and the fight
did not come. People argued about what
to do with the number, which is a much better
conversation and not one I was prepared for.
-
On MCP, where I have been mostly critical, I wrote the
other half: the good parts of MCP are prompts and resources. Everyone implements tools and ignores the two
primitives that carry context. If you are weighing
skills against MCP, weigh this — a skill can hold a
prompt, but resources are the part nobody is
replicating.
-
Elsewhere: when AI agents start acting, APIs become execution
contracts. What three models say about sixty-five API
providers — I asked three of them the same questions about the
same catalog and compared the answers. Plumma carries CAMARA's vocabulary without its
endpoints, which is the standards-adoption failure mode I keep
finding: the nouns arrive, the contract does not. Google makes the machine credential scriptable and
the OAuth client console-only — the onboarding series, still finding the same
door.
-
And two that are not about APIs at all: I am anti-AI and I run my business on it, and forcing people to prove they are robots when you
are all in on AI.
The thing I keep turning over after Toronto: every person
in that room already knew their access policies were thin.
Nobody was surprised by the score. The gap is not
knowledge and it is not tooling — we have had policy
engines for a decade. It is that writing the policy has
never once been the thing anyone was rewarded for
shipping.
One in five. That number will not move because a fifth
framework arrives with seven stages.
See you next week.
🔌 APIs.io Influence — agent readiness across the whole
catalog — This issue is one long argument that the agent layer
is unmeasured. The measurement is the product: every
provider in the catalog scored on agent readiness, as
dimensions you can query rather than a number you have to
trust.
Single-provider reads are free, and always will be — look
up any one company, its APIs and its artifacts without a
key. Agent readiness across the catalog is the
part that is not, because ranking a field is a different
product from looking up a member of it.
The operation worth your week: find the
providers in your own stack, then look at which readiness
dimensions they actually fail — before you write another
integration against one.
curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/agent-readiness?limit=50" curl -H "X-API-Key: $KEY" "https://apis.io/api/v1/agent-readiness/dimensions"
Same data as the find_agent_readiness and agent_readiness_dimensions MCP tools. Note the keyless response is a 401, not a 402 — you need a key before the tier question even applies,
so log in with GitHub for a free Learn key first and see how much of the
catalog answers you for nothing. Influence is $499/mo, or $4,990/yr.
|