← All posts
§ Blog

Identity is the gate

HiTL for callable tools is identity as the gate, not a human in the thread. Admin-once client, user-scoped token. A PAT is not a headless agent.


Identity is the gate

I have sat in rooms where the security workaround was a Personal Access Token in a shared channel.

Not because anyone thought it was a good idea. Because the other option was to be the organisation owner. Bil Harmer, CISO, said it on the Claude post: the only way to use Supabase through Claude was to be an org owner or hand out Personal Access Tokens to everyone on the team.

That is not a human in the loop. That is a human in the way, until someone pastes a secret.

The scarce thing is not another consent screen. It is a gate you can name: who authorised the client, whose role is on the token, how fast revoke lands, and whether you can kill the job.

The workaround that looked like a policy

Per-user OAuth looks like control. Each person clicks Allow. Each grant lives on a laptop. Security cannot see the set. Offboarding means hoping the token expires.

The other workaround is worse. One owner connects the tool. Everyone else borrows that owner’s reach, or they get a PAT with no clock anyone will remember.

I already drew who decides to run in Headless agents and the ones who still call them. I already drew what loads at startup in The description is the trigger. This note is the third gate. A callable tool still needs an identity. If that identity is a pasted secret, you do not have a headless agent. You have a leak with a schedule.

What actually shipped

The occasion this week is Supabase. The contract is older than the tweet.

DateWhat is on the pageSource
18 Jun 2026Claude announces enterprise-managed authorisation for MCP connectors, Okta firstClaude blog
24 Aug 2026Same post marked generally available. Supabase listed among clients that support itClaude blog, update
24 Aug 2026Supabase marks enterprise-managed auth for its MCP server generally available on Team and Enterprise, with SSO. Authors: cemal_kilic, gregnrSupabase blog
(no date on the page)MCP blog calls the Enterprise-Managed Authorization extension stableMCP blog

The docs are the contract. An organisation owner authorises the MCP client once under Authorized Apps. The IdP issues an ID-JAG. Supabase exchanges that for a short-lived, non-refreshable access token. Access never exceeds the member’s existing permissions. The named clients on that page are Cursor and Claude. Team or Enterprise plus SSO are required.

That is the stack card. The rest of this note is the distinction, not the changelog.

Admin-once, user-scoped, revoke

Human-in-the-loop, for a callable tool, is not a person sitting in the thread. It is identity as the gate.

Admin-once client. User-scoped token. Revoke at the IdP.

Handed-out PAT versus identity as the gate

The member signs in the way they already sign in. The client asks the IdP for a grant scoped to the server. The server checks the grant against the owner’s authorisation and the member’s role, then issues a token that dies. When you need another, you repeat the exchange. There is no refresh token to hide in a vault and forget.

Without that, “we connected MCP” means one of two things. A queue of consent screens nobody can audit, or a PAT that outlives the person who pasted it.

With that, the questions an SLA can carry are ordinary:

  1. Who authorised the client for the organisation?
  2. Whose role is on this token?
  3. How fast does revoke land when the IdP says no?
  4. Can you kill the job that is already running?

The first three now have a page. The fourth does not.

DimensionHanded-out PAT, or owner-only OAuthIdentity as the gate
Who authorises the clientEach member, or the owner for themselvesOrganisation owner, once, under Authorized Apps
Whose role is on the tokenOften the owner’s, or a long-lived PATThe member’s existing role, nothing more
How you revokeHunt the token, hope it expiresIdP group, or remove the app
Unattended jobA leaked PAT with no clockStill a member token. No bot identity yet

What the docs still do not give you

I did not run this. There is no overnight receipt in the seed. The gaps below are what these pages do not claim. Naming them is the job.

There is no agent-action audit. You can see that a client was authorised, and that a member had a role. You cannot see, from these docs, who did what through MCP.

There is no service identity for a bot. Access is always a member. A headless job (a clock, a machine, nobody in the room) still has to wear someone’s badge, or it falls back to a PAT. That is the line. A PAT is not a headless agent.

There is no kill of a running job. Short-lived tokens limit how long a stolen grant lives. They do not stop a call that already started.

The IdP is still Okta-first. The Claude post says more identity providers are coming. Until they land, “we use EMA” is also “we use Okta.”

Those four gaps are why this is a field note and not a launch recap. The gate is real. The unattended side is not finished.

What enterprises could steal

You do not need this connector. You need the four questions.

  1. Write the gate as identity, not as a person in the chat. Admin-once client. User-scoped token. Revoke at the IdP. If the workaround is a PAT in Slack, you do not have HiTL. You have a secret with a name.
  2. Put the owner action on Authorized Apps, or the equivalent, and treat that row as the audit surface for “who let this client in.” One owner. One client. A date.
  3. Refuse a token that is wider than the member’s existing role. If the tool can do more than the person can do in the product, the gate failed before the model spoke.
  4. Time the revoke. Deprovision in the IdP. Measure how long the MCP call still works. That number is the SLA, not the blog sentence.
  5. Do not call a scheduled job headless if it cannot bind to this gate. A bot with no service identity is a leaked PAT with a cron. Keep a human badge on it, or do not run it unattended.

What this post is not

This is not a recap of a tweet. It is not a remake of the description-as-trigger note, and it is not the called-versus-invoked note. Those two gates still stand. This one sits under them: whose identity is on the call.

It is not a claim that I wired Okta to a server overnight. The pages are public. The overnight run, with a bot that has its own identity and a kill switch, is a later note.

The product question is no longer whether the connector is generally available. It is whether you can answer the four SLA questions without opening a shared PAT.


Field note from the build-in-public log. NDA-safe, no client names, rounded figures only. If this matches what you are seeing, get in touch.

§

BELOW THE LINE

PODČÁRNÍK · SIDEWAYS GLANCE, NOT A SUMMARY

On the colleague who kept the PAT in Slack

They called it a temporary exception. Temporary is a kind word for a secret that has a channel, a pin, and three people who have left.

The alternative was to be the owner. Owners are busy. Owners forward the token. That is how PATocracy starts. Not with a breach. With a workaround that survives the meeting because nobody wants to be the person who blocks Claude.

HR used to mint badges that opened every door on the floor. The PAT is that habit, moved into a header. The model did not steal it. A helpful person pasted it so the demo would run.

I have sat in rooms where the remedy was another approval screen. Click Allow. Click Allow again. A small society of consents, none of them on a list the CISO can revoke on a Tuesday. The missing hire was a gate. The missing gate was whose name is on the token.

Nobody got fired for a PAT that still worked. That is why the PATs persist.

ČESKY — ORIGINAL PODČÁRNÍK

O kolegovi, který držel PAT ve Slacku

Říkali tomu dočasnou výjimku. Dočasné je laskavé slovo pro tajemství, které má kanál, připíchnutí a tři lidi, co už odešli.

Druhá možnost byla být owner. Ownery to nezajímá. Owner token přepošle. Tak začíná PATokracie. Ne incidentem. Workaroundem, který přežije schůzku, protože nikdo nechce být ten, kdo zablokuje Claude.

Personalistika uměla odznaky, které otevíraly všechny dveře na patře. PAT je tentýž zvyk, jen v headeru. Model ho neukradl. Ochotný člověk ho vložil, aby demo běželo.

Seděl jsem v místnostech, kde lékem byla další obrazovka Allow. Allow znovu. Malá společnost souhlasů, žádný z nich na seznamu, který CISO zruší v úterý. Chyběla brána. V bráně chybělo, čí jméno je na tokenu.

Za PAT, který pořád fungoval, nikoho nevyhodili. Proto PAT drží.