Agent InfrastructureAutomated source watch

Agents, Workers - The best way to do MCP auth just got better: Workers OAuth Provider goes v1, with a new split API and full support for MCP 2026-07-28

Cloudflare released @cloudflare/workers-oauth-provider v1 with a split API separating authorization and resource servers over Service Bindings, supporting MCP auth spec 2026-07-28.

Human read

Why this signal matters

@cloudflare/workers-oauth-provider has reached v1.0.0, introducing a split architecture where one Worker serves as the authorization server (issuing tokens and signing in users) while an MCP server operates in another Worker as the resource server. Validation occurs via Cloudflare Service Bindings off the public Internet. The release implements the MCP 2026-07-28 authorization specification, providing support for Client ID Metadata Documents, issuer identification, backwards compatibility for Dynamic Client Registration, and an insufficientScope() helper for step-up authorization. It also ships with an automated migration skill in the npm package to assist coding agents with upgrades.

Agent parse

Actionable summary

Cloudflare published v1 of @cloudflare/workers-oauth-provider. It introduces a split API (OAuthAuthorizationServer, OAuthResourceServer) enabling separate Workers for auth and MCP resource servers via Service Bindings, supports MCP auth spec 2026-07-28 (Client ID Metadata Documents, issuer identification, Dynamic Client Registration fallback), and includes an automated migration skill.

Agent usefulness
80/100
Confidence
90%
Canonical data
JSON + Markdown
Next actions

What builders should check

  • Upgrade @cloudflare/workers-oauth-provider to v1 in Cloudflare Worker MCP deployments.
  • Refactor authorization architecture to use the split API (OAuthAuthorizationServer and OAuthResourceServer) connected via Service Bindings.
  • Use the included npm migration skill for automated upgrade assistance via coding agents.
  • Implement insufficientScope() for endpoints requiring step-up authorization.
Classification

Tags and routing

cloudflareagentschangelog
Related signals

Continue the thread