Identity is the gate
HiTL for callable tools is identity as the gate, not a human in the thread. Admin-once client, user-scoped token. A PAT is not a headless agent.
Identity is the gate
I have sat in rooms where the security workaround was a Personal Access Token in a shared channel.
Not because anyone thought it was a good idea. Because the other option was to be the organisation owner. Bil Harmer, CISO, said it on the Claude post: the only way to use Supabase through Claude was to be an org owner or hand out Personal Access Tokens to everyone on the team.
That is not a human in the loop. That is a human in the way, until someone pastes a secret.
The scarce thing is not another consent screen. It is a gate you can name: who authorised the client, whose role is on the token, how fast revoke lands, and whether you can kill the job.
The workaround that looked like a policy
Per-user OAuth looks like control. Each person clicks Allow. Each grant lives on a laptop. Security cannot see the set. Offboarding means hoping the token expires.
The other workaround is worse. One owner connects the tool. Everyone else borrows that owner’s reach, or they get a PAT with no clock anyone will remember.
I already drew who decides to run in Headless agents and the ones who still call them. I already drew what loads at startup in The description is the trigger. This note is the third gate. A callable tool still needs an identity. If that identity is a pasted secret, you do not have a headless agent. You have a leak with a schedule.
What actually shipped
The occasion this week is Supabase. The contract is older than the tweet.
| Date | What is on the page | Source |
|---|---|---|
| 18 Jun 2026 | Claude announces enterprise-managed authorisation for MCP connectors, Okta first | Claude blog |
| 24 Aug 2026 | Same post marked generally available. Supabase listed among clients that support it | Claude blog, update |
| 24 Aug 2026 | Supabase marks enterprise-managed auth for its MCP server generally available on Team and Enterprise, with SSO. Authors: cemal_kilic, gregnr | Supabase blog |
| (no date on the page) | MCP blog calls the Enterprise-Managed Authorization extension stable | MCP blog |
The docs are the contract. An organisation owner authorises the MCP client once under Authorized Apps. The IdP issues an ID-JAG. Supabase exchanges that for a short-lived, non-refreshable access token. Access never exceeds the member’s existing permissions. The named clients on that page are Cursor and Claude. Team or Enterprise plus SSO are required.
That is the stack card. The rest of this note is the distinction, not the changelog.
Admin-once, user-scoped, revoke
Human-in-the-loop, for a callable tool, is not a person sitting in the thread. It is identity as the gate.
Admin-once client. User-scoped token. Revoke at the IdP.

The member signs in the way they already sign in. The client asks the IdP for a grant scoped to the server. The server checks the grant against the owner’s authorisation and the member’s role, then issues a token that dies. When you need another, you repeat the exchange. There is no refresh token to hide in a vault and forget.
Without that, “we connected MCP” means one of two things. A queue of consent screens nobody can audit, or a PAT that outlives the person who pasted it.
With that, the questions an SLA can carry are ordinary:
- Who authorised the client for the organisation?
- Whose role is on this token?
- How fast does revoke land when the IdP says no?
- Can you kill the job that is already running?
The first three now have a page. The fourth does not.
| Dimension | Handed-out PAT, or owner-only OAuth | Identity as the gate |
|---|---|---|
| Who authorises the client | Each member, or the owner for themselves | Organisation owner, once, under Authorized Apps |
| Whose role is on the token | Often the owner’s, or a long-lived PAT | The member’s existing role, nothing more |
| How you revoke | Hunt the token, hope it expires | IdP group, or remove the app |
| Unattended job | A leaked PAT with no clock | Still a member token. No bot identity yet |
What the docs still do not give you
I did not run this. There is no overnight receipt in the seed. The gaps below are what these pages do not claim. Naming them is the job.
There is no agent-action audit. You can see that a client was authorised, and that a member had a role. You cannot see, from these docs, who did what through MCP.
There is no service identity for a bot. Access is always a member. A headless job (a clock, a machine, nobody in the room) still has to wear someone’s badge, or it falls back to a PAT. That is the line. A PAT is not a headless agent.
There is no kill of a running job. Short-lived tokens limit how long a stolen grant lives. They do not stop a call that already started.
The IdP is still Okta-first. The Claude post says more identity providers are coming. Until they land, “we use EMA” is also “we use Okta.”
Those four gaps are why this is a field note and not a launch recap. The gate is real. The unattended side is not finished.
What enterprises could steal
You do not need this connector. You need the four questions.
- Write the gate as identity, not as a person in the chat. Admin-once client. User-scoped token. Revoke at the IdP. If the workaround is a PAT in Slack, you do not have HiTL. You have a secret with a name.
- Put the owner action on Authorized Apps, or the equivalent, and treat that row as the audit surface for “who let this client in.” One owner. One client. A date.
- Refuse a token that is wider than the member’s existing role. If the tool can do more than the person can do in the product, the gate failed before the model spoke.
- Time the revoke. Deprovision in the IdP. Measure how long the MCP call still works. That number is the SLA, not the blog sentence.
- Do not call a scheduled job headless if it cannot bind to this gate. A bot with no service identity is a leaked PAT with a cron. Keep a human badge on it, or do not run it unattended.
What this post is not
This is not a recap of a tweet. It is not a remake of the description-as-trigger note, and it is not the called-versus-invoked note. Those two gates still stand. This one sits under them: whose identity is on the call.
It is not a claim that I wired Okta to a server overnight. The pages are public. The overnight run, with a bot that has its own identity and a kill switch, is a later note.
The product question is no longer whether the connector is generally available. It is whether you can answer the four SLA questions without opening a shared PAT.
Field note from the build-in-public log. NDA-safe, no client names, rounded figures only. If this matches what you are seeing, get in touch.
§
BELOW THE LINE
PODČÁRNÍK · SIDEWAYS GLANCE, NOT A SUMMARY
On the colleague who kept the PAT in Slack
They called it a temporary exception. Temporary is a kind word for a secret that has a channel, a pin, and three people who have left.
The alternative was to be the owner. Owners are busy. Owners forward the token. That is how PATocracy starts. Not with a breach. With a workaround that survives the meeting because nobody wants to be the person who blocks Claude.
HR used to mint badges that opened every door on the floor. The PAT is that habit, moved into a header. The model did not steal it. A helpful person pasted it so the demo would run.
I have sat in rooms where the remedy was another approval screen. Click Allow. Click Allow again. A small society of consents, none of them on a list the CISO can revoke on a Tuesday. The missing hire was a gate. The missing gate was whose name is on the token.
Nobody got fired for a PAT that still worked. That is why the PATs persist.
ČESKY — ORIGINAL PODČÁRNÍK
O kolegovi, který držel PAT ve Slacku
Říkali tomu dočasnou výjimku. Dočasné je laskavé slovo pro tajemství, které má kanál, připíchnutí a tři lidi, co už odešli.
Druhá možnost byla být owner. Ownery to nezajímá. Owner token přepošle. Tak začíná PATokracie. Ne incidentem. Workaroundem, který přežije schůzku, protože nikdo nechce být ten, kdo zablokuje Claude.
Personalistika uměla odznaky, které otevíraly všechny dveře na patře. PAT je tentýž zvyk, jen v headeru. Model ho neukradl. Ochotný člověk ho vložil, aby demo běželo.
Seděl jsem v místnostech, kde lékem byla další obrazovka Allow. Allow znovu. Malá společnost souhlasů, žádný z nich na seznamu, který CISO zruší v úterý. Chyběla brána. V bráně chybělo, čí jméno je na tokenu.
Za PAT, který pořád fungoval, nikoho nevyhodili. Proto PAT drží.