Centrally manage authorization for MCP connectors
Summary
On June 18, 2026, a new enterprise-managed authorization feature was released for Model Context Protocol (MCP) connectors, enabling organizations to centrally provision access for Claude users. This update allows administrators to manage MCP connector authorization through their identity provider, initially supporting Okta, eliminating the need for individual user authorization. Previously, users had to manually authorize connectors after an admin enabled them. Now, users automatically inherit access based on their existing IdP groups and roles, resulting in a "zero-touch" setup experience across Claude chat, Claude Code, and Cowork. This system integrates MCP access management into existing IT workflows, enhancing security by allowing faster revocation and ensuring connectors adhere to established access controls. Several MCP providers, including Asana, Atlassian, Canva, Figma, Granola, Linear, and Supabase, support this feature at launch, with Hubspot, Ramp, and Webflow among the early adopters.
Key takeaway
For AI Architects or IT Professionals deploying Claude within an enterprise, this new enterprise-managed authorization feature significantly simplifies connector rollout and enhances governance. You can now provision MCP connectors centrally via your identity provider, like Okta, eliminating per-user authorization steps and integrating AI tool access into existing security policies. This streamlines onboarding for your 2,000 employees, ensures faster access revocation, and maintains a clear separation between work and personal tool usage. Consider adopting this beta feature to scale AI capabilities securely and efficiently across your organization.
Key insights
Centralized IdP-driven authorization for AI connectors streamlines access, enhances security, and simplifies enterprise deployment.
Principles
- Authorization via IdP groups ensures consistent access.
- Open standards facilitate broad ecosystem adoption.
- Centralized management improves security posture.
Method
Admins connect their identity provider (e.g., Okta) to Claude, then select which MCP connectors to enable for their organization. User access is automatically provisioned based on IdP roles.
In practice
- Integrate MCP connector access into existing IdP workflows.
- Shorten access token lifetimes for faster deprovisioning.
- Enforce IdP-only connections for work/personal separation.
Topics
- Model Context Protocol
- Enterprise Authorization
- Identity Management
- Okta Integration
- Claude AI Connectors
- Access Provisioning
Best for: CTO, VP of Engineering/Data, Executive, IT Professional, AI Architect, AI Security Engineer
Related on AIssential
Editorial summary, takeaway, and curation by AIssential. Original article published by Claude Blog.