# Bringing Strong Authentication and Granular Authorization for GenAI - Dan Moore - ASW #369 Page: https://stenobird.com/podcast/application-security-weekly-audio-436682/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369 Text version: https://stenobird.com/podcast/application-security-weekly-audio-436682/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369.md Podcast: [Application Security Weekly (Audio)](https://stenobird.com/podcast/application-security-weekly-audio-436682) Published: 2026-02-10T10:00:00+00:00 Episode link: https://aswaudio.libsyn.com/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369 Audio file: https://dts.podtrac.com/redirect.mp3/traffic.libsyn.com/secure/aswaudio/ASW_369_1--3f3add95-6740-4076-94ac-4e704e6b4cc5--audio-converted--a2a40f04-b885-4b23-af7c-7f591c19a0e7.mp3?dest-id=626765 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/application-security-weekly-audio-436682/episodes/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369 Duration seconds: 4164 ## Resource When it comes to agents and MCPs, the interesting security discussion isn't that they need strong authentication and authorization, but what that authn/z story should look like, where does it get implemented, and who implements it. Dan Moore shares the useful parallels in securing APIs that should be brought into the world of MCPs -- especially because so many are still interacting with APIs. Resources https://stackoverflow.blog/2026/01/21/is-that-allowed-authentication-and-authorization-in-model-context-protocol/ https://fusionauth.io/articles/identity-basics/authorization-models Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-369 ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/application-security-weekly-audio-436682/episodes/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/application-security-weekly-audio-436682/bringing-strong-authentication-and-granular-authorization-for-genai-dan-moore-asw-369.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.