Skip to main content
New

1 minute read

Agents can read your own workspace record after sign-in

The signed-in part of the public Model Context Protocol (MCP) server and the A2A agent is live: an agent with an OAuth access token from Trooth's sign-in provider can read your own workspace's company record and keep A2A tasks for 24 hours. No scope is required.

What changed

Both protected-resource metadata documents now answer and name Trooth's WorkOS AuthKit authorization server. A client registers itself there, through dynamic client registration or a client ID metadata document, and requests a token with the MCP server or the A2A agent as the resource. No scope is required: AuthKit does not grant custom scopes to a client that registers itself, so none is asked for. Every token is still checked for its issuer, its audience, its signature, its expiry, its client and its subject. trooth_my_company_record reads only the workspace linked to the token's subject, a link made when that person signs in to trooth.co with Continue with enterprise SSO; until then it answers not_linked. The A2A agent keeps a task for a token holder for 24 hours, readable only by that subject and client.

Why it changed

Until October 5, 2026 no authorization server was configured, so these parts answered that sign-in was not configured. Trooth sign-in now runs on WorkOS AuthKit in production, which is also an OAuth authorization server for agents.

Who is affected

  • Affected: Developers and agents calling the MCP server at api.trooth.co/public/mcp or the A2A agent at api.trooth.co/a2a/v1. The public tools and the A2A skills are unchanged and still need no token.
  • Availability: Public, at api.trooth.co. Reading your own record needs a workspace member who has signed in to trooth.co with enterprise single sign-on (SSO), using Continue with enterprise SSO.
  • Release stage: Available.
  • Areas: API, Company workspace.

What to do

No action required. Nothing is required. To use the signed-in tool, let your client register itself with the authorization server the protected-resource metadata names, and sign in to trooth.co once with Continue with enterprise SSO to link your workspace.

Dates

  • Announced: October 5, 2026, the day this entry was written. Entries are never backdated.
  • Released: October 5, 2026.

Read more

Follow what changes at Trooth

Every entry by email, or a feed narrowed to one area or to the changes that need you to act.

Product updates by email

Occasional notes when something on this page changes. You get one confirmation email when you subscribe, every email carries an unsubscribe link, and the address is never sold or shared.

RSSAPI onlyNeeds action

View as agent