Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Venue: Emerald Room (Level 1) clear filter
arrow_back View All Dates
Friday, September 18
 

10:20 CEST

Potential Issues for Cross-domain Multi-hop API Calls and Their Solution Proposal - Takashi Norimatsu, Hitachi, Ltd.
Friday September 18, 2026 10:20 - 10:45 CEST
When an MCP server calls an API server requiring an access token in a different domain, elicitation in URL mode is defined by the MCP. Furthermore, token exchange is also used in real-world use cases. We describes the security and operational issues associated with these two methods and proposes solutions.

Elicitation in URL mode may cause user swapping. Moreover, even if an authorization server performing the initial authorization securely perform it by following MCP spec, the well-known attacks may succeed if the other authorization server performing the external authorization does not care about security.

Token exchange may cause information leaks, fraudulent access token use, and availability problems.

In both methods, there are two access tokens: for accessing the MCP server, for accessing the API server. To detect user swapping, it is needed to ensure that both users bound with the first and second token are the same. However, even if the same user registered in both different domains, their user identifiers are usually different. Therefore, simply matching them exactly is not effective.

We describe these issues and propose their solutions.
Speakers
avatar for Takashi Norimatsu

Takashi Norimatsu

Chief OSS Specialist, Hitachi, Ltd.
Takashi Norimatsu, PhD in Engineering, Chief OSS Specialist, Hitachi, Ltd. is a maintainer of Keycloak. He has been implemented and contributed security features like Financial-grade API (FAPI) security profiles, Passkeys, Model Context Protocol (MCP) support. He leads Keycloak's... Read More →
Friday September 18, 2026 10:20 - 10:45 CEST
Emerald Room (Level 1)

10:55 CEST

ID-JAG: Solving OAuth Sprawl for Enterprise AI Agents - Joey Orlando, Archestra.AI & Aaron Parecki, Okta
Friday September 18, 2026 10:55 - 11:20 CEST
Enterprise AI agents are moving from demos into production, and auth is becoming a blocker. Demo agents can connect to tools with OAuth, but real enterprise agents may need SaaS services for thousands of employees. Per-user, per-service consent does not scale.

This session explains ID-JAG, the Identity Assertion JWT Authorization Grant pattern behind MCP's Enterprise-Managed Authorization extension. ID-JAG turns an existing SSO login into centrally governed, auditable access to approved MCP servers, without repeated OAuth prompts.

We'll cover the production problem, protocol flow, and lessons from implementing ID-JAG support in Archestra, one of the first MCP clients to support it. We'll also discuss what identity provider support enables.

Attendees will leave with a model for production agent auth: one SSO login, centralized policy, scoped MCP-native access tokens, fewer consent screens, and a cleaner security review story.

We'll close with the missing piece: SaaS provider adoption. To unlock enterprise deployments, authorization servers need to support this flow so agents can access approved business systems without key-sharing, manual credentials, or one-off integrations.
Speakers
avatar for Joey Orlando

Joey Orlando

Co-Founder, Archestra.AI
Co-Founder of Archestra.AI - previous engineer on the Grafana IRM team. Active member of the MCP contributors community, currently involved in the Enterprise and tool annotation working groups.

Prior to software, worked as a biochemist for several years :)
avatar for Aaron Parecki

Aaron Parecki

Director of Identity Standards, Okta
Aaron Parecki is Director of Identity Standards at Okta and active in multiple standards development organizations, including IETF, OpenID Foundation, W3C, and MCP. He is an editor of several other OAuth specifications, and has been influential in shaping how MCP has adopted OAuth... Read More →
Friday September 18, 2026 10:55 - 11:20 CEST
Emerald Room (Level 1)

11:30 CEST

Economies of Scale for MCP and Agents: Why You Need an Identity Broker - Magnus Jungsbluth & Jan Brennenstuhl, Zalando SE
Friday September 18, 2026 11:30 - 11:55 CEST
Drawing from lessons of how to scale an enterprise to thousands of microservices, we make the case that pushing concerns to the infrastructure for agentic systems should be a no-brainer when planning to scale agentic systems.
This talk explores how Zalando tackled this challenge by building and open-sourcing our own agentic identity broker as part of our broader agentic platform initiative. We will share how it supports delegation chains across third-party and in-house applications, integrates with the CNCF project agentgateway and how it allows us to keep these pesky authentication / authorization concerns on the infrastructure and keep MCP servers and agents simple.
We will dive into the technical mechanics, how it integrates into a larger enterprise and allows us to apply just enough governance to stay ahead of the game. We will cover practical applications and limitations of dynamic client registration.
A closing outlook will illustrate how tool approvals and human-in-the-loop can be enforced centrally without agent authors or MCP authors having to build anything. Practical examples of CIBA and intent-based access will complete the session.
Speakers
avatar for Magnus Jungsbluth

Magnus Jungsbluth

Senior Principal Engineer, Zalando SE
Magnus has been working for over two decades in software engineering with a strong focus on security and cryptography. At Bundesdruckerei he led a platform team for trust center applications. Since joining Zalando he leads initiatives to build more platform capabilities around security... Read More →
avatar for Jan Brennenstuhl

Jan Brennenstuhl

Principal Software Engineer, Zalando SE
Jan Brennenstuhl is a Principal Engineer and product-minded security enthusiast with a proven track record of building identity solutions for millions of users while balancing UX and security in high-stakes revenue funnels. Currently focused on making the agentic SDLC more secure... Read More →
Friday September 18, 2026 11:30 - 11:55 CEST
Emerald Room (Level 1)

12:05 CEST

MCP Apps and the Nearly Headless Web - Liad Yosef, MCP Apps
Friday September 18, 2026 12:05 - 12:30 CEST
MCP Apps are the last piece in moving toward a new web - one that's "nearly" headless. Autonomous agents, not humans, will interact with most websites through MCP, APIs, and other data channels. Websites and browsers become obsolete, replaced by personal assistants that orchestrate tasks on our behalf. In rare cases, agents will fall back to browser capabilities to navigate sites that aren't yet agent-ready.
But we'll still need the last mile.
Some moments still require human eyes and human input: choosing a seat at a venue, completing a check-in, reviewing a 3D model, verifying intent on important decisions. This is where MCP Apps come in - letting tools, websites, and services send composable, interactive chunks of UI directly to agents, exactly when needed, maintaining brand and identity.
We'll explore the full cycle of this nearly headless web: the infrastructure required to support autonomy and trust, the new UI layer, and how assistants are becoming the new browsers.
MCP Apps redefine the web's interface. Headless, but with a human eye at the end.
Speakers
avatar for Liad	Yosef

Liad Yosef

Co-creator, MCP Apps
Liad Yosef is the co-author and maintainer of MCP Apps on the MCP Steering Committee. He is the co-builder of MCP-UI, and previously AI Lead in Shopify's CEO office. Liad is currently a co-founder and CTO, building the future of agentic interfaces at Ora. Liad is a web enthusiast... Read More →
Friday September 18, 2026 12:05 - 12:30 CEST
Emerald Room (Level 1)

12:40 CEST

From API Catalogs To Agent Catalogs: Solving MCP Server Discovery With Open Resource Discovery - Vyshnavi Gadamsetti & Sebastian Wennemers, SAP SE
Friday September 18, 2026 12:40 - 13:05 CEST
As MCP servers multiply, the ecosystem is hitting the fragmentation problem APIs hit a decade ago: every server is a point-to-point integration with no shared way to discover or describe it. Live introspection over a connected session does not scale to the catalogs, registries, and gateways that need to reason about thousands of servers without starting each one up. Open Resource Discovery (ORD) solved this for APIs, events, and data products. Each resource publishes a static, machine-readable description at a well-known endpoint. Aggregators crawl those descriptions and build catalogs that registries and gateways can query without connecting to the resource. Recent ORD work applies the same shape to agents and the MCP servers they depend on, scoping the dependency to the tools and prompts an agent uses. The same pattern fits MCP. The talk walks through a Server Card design that serves tools, prompts, and resources alongside metadata from a well-known endpoint, so registries and gateways can reason about a server before any agent connects. The design has been contributed into the open MCP community via SEP-2127, with a public renderer and playground demonstrating it end-to-end.
Speakers
avatar for Vyshnavi Gadamsetti

Vyshnavi Gadamsetti

Software Development Architect, SAP SE
Vyshnavi Gadamsetti is a software architect at SAP, where she has worked for 14 years across enterprise software. Earlier in her career, she worked at PwC. Her current work spans MCP (Model Context Protocol), ORD (Open Resource Discovery), agent extensibility and governance, and the... Read More →
avatar for Sebastian Wennemers

Sebastian Wennemers

Chief Architect, SAP SE
Sebastian Wennemers has 15+ years of experience in building and architecting solutions that need a solid metadata foundation. He is currently driving SAPs metadata story that grounds the AI strategy.
Friday September 18, 2026 12:40 - 13:05 CEST
Emerald Room (Level 1)

13:15 CEST

Spotify’s Bet on MCP and Investment in Open Source - Oliver Soell & Yannick Epstein, Spotify
Friday September 18, 2026 13:15 - 13:40 CEST
Spotify’s workforce went from zero to near universal use of MCP servers in breakneck time. It was only possible due to the MCP gateway - custom code written in a weekend to support the urgent need to expose Spotify’s extensive internal API ecosystem to AI agents.

The MCP gateway rapidly became a victim of its own success; multiple teams were committing significant changes to the codebase, and domain ownership and on-call support for the gateway were somewhat uncertain. From a sustainability perspective, the MCP gateway was becoming a big risk.

In this talk you’ll learn how Spotify successfully rebased its highly custom MCP gateway use case onto OSS technologies, while retaining deep integration into Spotify’s infrastructure management plane, service discovery, and microservice ecosystem. Hear how kgateway, the Envoy proxy, kro, and the Gateway API were used to build the new MCP gateway, enabling it to be better sustained by the right teams contributing their specific expertise.
Speakers
avatar for Oliver Soell

Oliver Soell

Software Engineer, Spotify
Infrastructure at Spotify
avatar for Yannick Epstein

Yannick Epstein

Senior Software Engineer, Spotify
Yannick Epstein is a Senior Engineer in Spotify’s Core Infrastructure group, where he works on systems that manage traffic and communication between backend services. He led the discovery and engineering effort for Spotify’s custom xDS control plane and the company’s dynamic... Read More →
Friday September 18, 2026 13:15 - 13:40 CEST
Emerald Room (Level 1)

15:45 CEST

Attribution by Design: Skills, MCP, and Where Provenance Gets Built In - Ola Hungerford, Model Context Protocol
Friday September 18, 2026 15:45 - 16:10 CEST
Agents increasingly draw on specialized human knowledge at inference time, and the infrastructure delivering it is converging around Skills, MCP, and very often a mix of the two. That makes these standards a decision point: provenance either travels with the knowledge or its absence becomes the default.

The MCP community is standardizing two complementary efforts: Interceptors (deterministic hooks in clients, servers, and gateways) and how, why, and when to serve Skills over MCP. This talk shows how the two fit together to standardize attribution for human expertise and other content encoded as Skills and related inference-time formats.

The talk showcases two examples:
- An attribution gateway that validates and records authorship in a centralized control plane
- A standardized client-side hook to log and credit authors when Skills are invoked
Speakers
avatar for Ola Hungerford

Ola Hungerford

Maintainer, Model Context Protocol
Ola Hungerford is a Principal Engineer at Nordstrom and a maintainer and community moderator for the Model Context Protocol. She leads AI enablement initiatives while contributing to MCP's specification, developer tooling, documentation, and community governance. Ola comes from a... Read More →
Friday September 18, 2026 15:45 - 16:10 CEST
Emerald Room (Level 1)

16:20 CEST

Observability Meets MCP: Patterns, Gaps, and Standards - Matthias Loibl, Polar Signals
Friday September 18, 2026 16:20 - 16:45 CEST
Almost every observability project and vendor has shipped an MCP server in the past year.
Prometheus, Jaeger, and OpenTelemetry sit next to Grafana, Datadog, Honeycomb, Polar Signals, and a long list of others. This talk puts a few dozen of them side by side: how they handle transport, auth, tool design, and read/write access, and which ones do something genuinely interesting.

The data is what makes observability hard. Time series, distributed traces, and profiles are dense, high-cardinality, and deeply nested, and wrapping a JSON API in a few tools doesn't make any of that easier for an LLM to read. We'll look at how different servers represent these
signals, and what makes one format easy for a model to reason over while another just fills up the context window. We won't be proposing a new standard. The goal is to surface the best implementation patterns the industry has already converged on, so the audience can judge which observability MCP server to adopt (or build a better one themselves).
Speakers
avatar for Matthias Loibl

Matthias Loibl

Director of Cloud, Polar Signals
Matthias Loibl is the Director of Cloud at Polar Signbals. He works on cloud-native observability. He was previously at Red Hat and Kubermatic and maintains many projects, such as Prometheus, Thanos, Prometheus Operator, and Parca. He enjoys working on Distributed Systems with Go... Read More →
Friday September 18, 2026 16:20 - 16:45 CEST
Emerald Room (Level 1)

16:55 CEST

MCP Challenges & Opportunities - Sam Morrow, GitHub; Angie Jones, Agentic AI Foundation; Shaun Smith, Hugging Face
Friday September 18, 2026 16:55 - 17:20 CEST
Join Jeremiah Lowin (Fast MCP), Shaun Smith (fast-agent) and Sam Morrow (GitHub MCP) for a panel on the challenges and opportunities of shipping MCP, hosted by Angie Jones, VP of Developer Experience at the AAIF.

By bringing perspectives from server, SDK and agent harness developers together in the same panel, you’ll see where their experiences align, l where they diverge, where they see the protocol heading and what they’re excited about.
Speakers
avatar for Sam Morrow

Sam Morrow

Senior Software Engineer, GitHub
Sam is a Senior Software Engineer at GitHub, where he leads development of the GitHub MCP server. He works on AI developer tools and helps shape agentic workflows at GitHub. In a past life he was also a professional drummer.
avatar for Angie Jones

Angie Jones

VP, DX, Agentic AI Foundation
Angie Jones is the VP of Developer Experience at the Agentic AI Foundation where she guides how agentic systems are designed, implemented, and adopted across the global developer ecosystem.

Angie is an international keynote speaker who shares her wealth of knowledge at software... Read More →
avatar for Shaun Smith

Shaun Smith

Open Source Agents / MCP, Hugging Face
Shaun leads Open Source/MCP at Hugging Face, and is an MCP Steering Committee member serving as a Community Moderator and Transports Working Group. He is also the author of `fast-agent` - one of the few clients with comprehensive protocol support and diagnostic capabilities.
Friday September 18, 2026 16:55 - 17:20 CEST
Emerald Room (Level 1)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -