Loading…
17-18 September | Amsterdam, Netherlands
View More Details & Registration

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.
Friday September 18, 2026 10:20 - 10:45 CEST
When an MCP server calls an API server requiring an access token in a different domain, elicitation in URL mode is defined by the MCP. Furthermore, token exchange is also used in real-world use cases. We describes the security and operational issues associated with these two methods and proposes solutions.

Elicitation in URL mode may cause user swapping. Moreover, even if an authorization server performing the initial authorization securely perform it by following MCP spec, the well-known attacks may succeed if the other authorization server performing the external authorization does not care about security.

Token exchange may cause information leaks, fraudulent access token use, and availability problems.

In both methods, there are two access tokens: for accessing the MCP server, for accessing the API server. To detect user swapping, it is needed to ensure that both users bound with the first and second token are the same. However, even if the same user registered in both different domains, their user identifiers are usually different. Therefore, simply matching them exactly is not effective.

We describe these issues and propose their solutions.
Speakers
avatar for Takashi Norimatsu

Takashi Norimatsu

Chief OSS Specialist, Hitachi, Ltd.
Takashi Norimatsu, PhD in Engineering, Chief OSS Specialist, Hitachi, Ltd. is a maintainer of Keycloak. He has been implemented and contributed security features like Financial-grade API (FAPI) security profiles, Passkeys, Model Context Protocol (MCP) support. He leads Keycloak's... Read More →
Friday September 18, 2026 10:20 - 10:45 CEST
Emerald Room (Level 1)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link