Start with Identity
← Blog
News

C1 ships enterprise-managed authorization, putting SSO in front of MCP agents

The identity platform formerly called ConductorOne now issues short-lived scoped tokens for MCP servers under the open enterprise-managed authorization extension, replacing per-server OAuth consent prompts with one governed enterprise login.

By SWI Community TeamJun 18, 2026Updated Aug 1, 2026

C1, the identity security platform that rebranded from ConductorOne in April 2026, has added support for enterprise-managed authorization, the open Model Context Protocol extension for governing how AI agents reach enterprise tools. Instead of each MCP server running its own OAuth consent prompt, users and agents authenticate once to C1, which issues short-lived scoped tokens built on the Cross-App Access standard for the servers they are entitled to. Anthropic shipped the first implementation in Claude and C1 supports it from day one. The control plane sets session length, applies fine-grained scope, and enforces re-authentication, and agents enter the same access reviews, approval workflows, and audit trail as people.

Why it matters

Per-server OAuth consent is the same mistake as per-application passwords, rediscovered for agents. Every MCP server that asks a user to click approve is an unmanaged trust relationship that no access review will ever see, and there is no revocation story beyond hunting through consent grants one integration at a time.

Enterprise-managed authorization is the federation answer applied to tool calls: one broker, short-lived scoped tokens, central revocation. That is the right shape, and it matters more that the extension is open than that C1 was first to it.

The practical caveat is coverage. A broker only governs the servers that implement the extension, and the estate a security team actually worries about is the long tail of internal MCP servers written last quarter. Inventory those first. See our guide to securing AI agent identities.

Source: GlobeNewswire

Independent analysis. No vendor sponsorship.