Case Study: Okta achieves secure zero-config MCP auth discovery with WorkOS AuthKit

A WorkOS Case Study

Preview of the Okta Case Study

Okta enables zero-config MCP auth in 2026 with WorkOS

Okta, a major enterprise identity provider, faced a challenge with the Model Context Protocol (MCP) standard. The initial authorization method, Dynamic Client Registration (DCR), created significant security vulnerabilities like SSRF attacks and client impersonation, which led Okta and other providers to disable it by default. This created a roadblock for seamless MCP interoperability.

WorkOS provided the solution through its AuthKit service and by implementing new spec revisions. They enabled Client ID Metadata Document (CIMD), which flipped the trust model and eliminated the dangerous registration endpoints. This allowed Okta to validate clients securely without manual pre-registration, closing a major category of security holes and establishing a sane, scalable security model for MCP connections.


View this case study…

WorkOS

82 Case Studies