Great timing, the blog post just went up! https://openid.net/call-for-participation-demonstrate-mcp-based-ai-agent-security-with-open-identity-standards-2/
On Tue, Jul 14, 2026 at 7:28 AM Joe DeCock <joe= [email protected]> wrote: > Thanks so much Aaron! That's very helpful. > > On Tue, Jul 14, 2026 at 10:01 AM Aaron Parecki <aaron= > [email protected]> wrote: > >> The set of resource authorization servers you found in the Okta >> announcement does not rely on any preconfigured trust relationships. The >> products are in various states of EA/beta/production, but you should be >> able to try it out with them as another IdP. Typically the feature is tied >> to an "enterprise" plan, so it might require contacting them rather than >> just doing a self-service signup. >> >> The OpenID Foundation AI Community Group is also planning an interop >> event in December which will include this spec. I don't think the blog post >> announcement is out yet but keep an eye out for it soon. >> >> There is also the testing tool at https://xaa.dev which helps test >> various combinations of the 3 roles. Unfortunately it doesn't yet support >> testing an external IdP, tho that is on the roadmap. >> >> I also set up a very rudimentary test resource (API, MCP, and >> authorization server) at https://motd.xaa.rocks which will run through >> the validation rules when processing an ID-JAG sent to it. >> >> Aaron >> >> >> >> On Tue, Jul 14, 2026 at 5:49 AM Joe DeCock <joe= >> [email protected]> wrote: >> >>> Hi all, >>> I'm interested in the current state of ID-JAG interoperability. In >>> particular, as an implementor of IdP authorization servers, I'd like to >>> test my implementation by integrating with real resource authorization >>> servers. >>> >>> Are there resources that would allow me to configure or signup with the >>> resource authorization server to do that? I've seen Okta's XAA feature, >>> including mention of an initial set of resource servers that can be used >>> with it. That seems to rely on Okta's existing trust relationships with >>> resource servers. >>> >>> Any pointers to resources would be appreciated and would be really >>> helpful to hopefully encourage interoperability and adoption. >>> >>> Cheers, >>> Joe >>> >> _______________________________________________ >>> OAuth mailing list -- [email protected] >>> To unsubscribe send an email to [email protected] >>> >>
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
