Blog
User and agent identity with MCP and ID-JAG
02/08/2026
When an agent reads a ticket or calls an internal API, the application needs to identify who initiated the access and which permissions apply. Static API keys and individual approvals need clear ownership. This article explains the approaches taken by MCP and ID-JAG.
MCP and authorisation
The MCP authorisation profile describes access to protected servers over HTTP. It builds on OAuth: the MCP server is the resource server, and the authorisation server issues access tokens. Local STDIO connections follow a different procedure. The connection alone does not enforce business policies for arbitrary agent actions.
ID-JAG: identity comes from the identity provider
The second building block is ID-JAG (Identity Assertion JWT Authorization Grant), an active draft of the IETF OAuth working group, built on proven standards (OAuth Token Exchange and the JWT Bearer Grant). Okta markets the pattern as Cross-App Access (XAA); the open foundation is ID-JAG.
The idea, in short: instead of every app and every agent asking every service for access individually, the enterprise identity provider issues the identity assertion. The agent or app presents this assertion to services that trust the same IdP and receives an access token in return, without numerous individual consent requests. The enterprise IdP remains the central source for user identities and their revocation; the client and the acting agent remain distinct contexts.
What this means for NomOS
Your installation connects user identities to the existing identity provider. The user, client and acting agent must remain distinguishable. We check supported authorisation mechanisms for the specific integration. ID-JAG is an integration option to assess, not a blanket promise for every installation.
Identity establishes who is accessing a resource. Policies must also define which actions are allowed and when a person decides. NomOS checks actions on execution paths integrated for that purpose. Event coverage, signing and evidence export are defined for the installation.
Three questions for every vendor
When selecting agent infrastructure, ask three questions: which open standards does it support? Can our identity provider manage identities and revoke access? Which information does it record so an action can be reviewed later?
For context: ID-JAG is an active draft standard and details may still change. An implementation therefore needs to check the supported version and its compatibility.
How NomOS governs agents: control agents through MCP. For further background, read our whitepaper.