But as I shepherded Clerk's MCP implementation across the line, the disillusionment began. OAuth has been around forever, and is a nearly infinite web of hundreds of different specs, all of which any given consumer or provider may or may not have implemented. There's no ubiquitous way for a provider to know which capacities a consumer wants (though there's an optional spec for that), and same in reverse (also an optional spec for that). There are enterprise grade security features that would probably be valuable for everyone but require alignment between the consumer and provider, so they never really get prioritized (outside of Okta).
Also, the specs change all the time. Especially the MCP spec - if either the consumer or provider side is expecting a different version, too bad. Not to mention that the specs a big and complex and extremely easy to mess up. Even the primary players are constantly messing it up with little bugs and de-syncing from various spec versions, many of which aren't exactly compatible.
While I was working on Clerk's MCP implementation, I found major MCP implementation bugs in both Cursor and Claude Code.
More recently, as a consumer of one of our vendors' MCPs, I noticed I was being signed out every day, they investigated, then came back to tell me that it was not their fault, and was actually a MCP bug in codex (
github.com/openai/codex/issu…).
The second I finished building one OAuth/MCP capability, another one would arrive in the spec that needed to be implemented. New consumers that wanted to use our MCPs were released constantly, many of them not spec compliant, then the user complaints start rolling in, which means you need to run off-spec compatibility workarounds, or just tell the users that they are out of luck until the client they are using fixes some bug.
Dynamic client registration was mandated in the initial version. It's a messy, insecure feature that no provider likes and makes apps much more prone to fraud and abuse. I was in the room when it was decided to try to replace it with something better (now out, CIMD). But DCR will still always need to be supported for compatibility.
It never ends. It never will end.