Uploaded December 2025 | Updated September 2026, 2 days ago
Modern AI agents don’t just respond to prompts — they need to act.
That means querying real systems, scheduling meetings, updating tickets, and working across the same SaaS tools your teams already use. But the moment an AI agent needs to act on a user’s behalf, you hit the hardest problem in enterprise AI:
authorization, consent, and governance.
In this talk, Garrett Galow (Product Manager at WorkOS) walks through a live MCP server demo that shows how delegated authorization actually works in practice — not as a concept, but against real enterprise systems like Linear and Google Calendar.
You’ll see how:
• MCP servers use tool calls and elicitation to request access only when needed
• Users explicitly grant consent per system, in real time
• Tokens are issued, rotated, and managed without exposing OAuth complexity to your application
• AI agents can safely impersonate users within clearly defined boundaries
This isn’t about building a scheduler. It’s about establishing the identity and authorization layer that makes MCP viable inside real organizations.
WorkOS Pipes acts as the enterprise identity substrate behind MCP:
• One API call to generate authorization URLs
• One API call to retrieve access tokens
• Automatic handling of refresh tokens, lifetimes, and rotation
• Clear consent flows and auditable access paths
The result is AI infrastructure that respects enterprise requirements around security, governance, and user trust — without forcing every team to re-implement OAuth and token management from scratch.
If you’re evaluating MCP, building AI agents that need real system access, or thinking about how these tools move from demo to production, this talk is for you.
Modern AI agents don’t just respond to prompts — they need to act.
That means querying real systems, scheduling meetings, updating tickets, and working across the same SaaS tools your teams already use. But the moment an AI agent needs to act on a user’s behalf, you hit the hardest problem in enterprise AI:
authorization, consent, and governance.
In this talk, Garrett Galow (Product Manager at WorkOS) walks through a live MCP server demo that shows how delegated authorization actually works in practice — not as a concept, but against real enterprise systems like Linear and Google Calendar.
You’ll see how:
• MCP servers use tool calls and elicitation to request access only when needed
• Users explicitly grant consent per system, in real time
• Tokens are issued, rotated, and managed without exposing OAuth complexity to your application
• AI agents can safely impersonate users within clearly defined boundaries
This isn’t about building a scheduler. It’s about establishing the identity and authorization layer that makes MCP viable inside real organizations.
WorkOS Pipes acts as the enterprise identity substrate behind MCP:
• One API call to generate authorization URLs
• One API call to retrieve access tokens
• Automatic handling of refresh tokens, lifetimes, and rotation
• Clear consent flows and auditable access paths
The result is AI infrastructure that respects enterprise requirements around security, governance, and user trust — without forcing every team to re-implement OAuth and token management from scratch.
If you’re evaluating MCP, building AI agents that need real system access, or thinking about how these tools move from demo to production, this talk is for you.










