AI Agents Need Authorization: The MCP Security Problem — Craig Cannon, Supabase | MCP Night @WorkOS
AI Agents Need Authorization: The MCP Security Problem — Craig Cannon, Supabase | MCP Night  @WorkOS
Uploaded December 2025 | Updated September 2026, 3 days ago
MCP isn’t just about fetching data.
It’s about who — or what — is allowed to act on production systems.

In this live demo, Craig Cannon, Head of DevRel and Marketing at Supabase, walks through Supabase’s MCP, showing how AI-native tools can operate directly against real infrastructure — not just read from it.

Craig demonstrates how MCP enables teams to:
• Query a live Postgres database using natural language
• Inspect application logs and authentication events
• Modify how data is presented to different users in real time
• Branch, report on, and reason over production systems without writing SQL

Using a playful Jingle All the Way scenario, Craig makes a serious point:
once MCP-style interfaces exist, authorization becomes the product.

The same MCP that lets you:
• Check whether a user is authenticated
• Inspect recent login activity
• Personalize responses based on identity

…can just as easily:
• Withhold or alter information for specific users
• Change system behavior based on who is asking
• Turn AI into an operator, not just an observer

That’s where enterprise reality shows up.

As MCP adoption accelerates, teams have to answer hard questions:
• What identities can MCP act on behalf of?
• What permissions apply to AI agents vs. humans?
• How do you audit and govern natural-language access to production systems?

This is where enterprise identity, access control, and policy enforcement stop being background infrastructure and become first-order concerns.

WorkOS exists to make that layer explicit, auditable, and enterprise-ready — so MCP-powered systems can move from impressive demos to safe production deployments.

If you’re evaluating MCP, AI-native databases, or agent-driven tooling, this session shows both the power — and the responsibility — that comes with it.
AI Agents Need Authorization: The MCP Security Problem — Craig Cannon, Supabase | MCP NightAI Builders with WorkOS, Daytona, and CoderAre we just Bags of Token Generation now? 🤖 #futureofwork #skillsWhy your Neon project might disappear #devtips #postgres #webdevStop Using Dynamic Client Registration for MCP — Den Delimarsky, Microsoft | MCP NightThe Hidden Cost of Token MaxingDexter Horthy (HumanLayer), Post-Event Interview | Dwarkesh UnpluggedWhy Postgres Became the Default Database — Sam Lambert, PlanetScale | re:Invent 2025Building Enterprise AI Agents with Kevin Coleman (Ravenna) & Michael Grinich | AIE Worlds Fair 2026The Internet Was Built to Stop ThisProtecting MCP Servers From Unauthorized AccessHow Marketing Teams Are Evolving with AI — Eran Dunsky, AppsFlyer | HumanX 2026
WorkOS |

AI Agents Need Authorization: The MCP Security Problem — Craig Cannon, Supabase | MCP Night

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER