そのユーザーで CompleteResourceTokenAuth を呼ぶ処理 “Session Binding URL: The URL pointing back to a customer-managed service that completes the session binding ... This endpoint is implemented and hosted by the customer.” AWS ML Blog「Secure AI agents with Amazon Bedrock AgentCore Identity on Amazon ECS」
を見せて開くことだけ • 始めた人と完了した人が同じかを確かめるのはサーバー(MUST) “The client's only responsibility is to provide the user with context about the elicitation URL the server wants them to open.” “the server MUST ensure that the user who started the elicitation request ... is the same user who completes the authorization flow.” https://modelcontextprotocol.io/specification/2025-11-25/client/elicitation
Identity の認可エンドポイントのまま Claude Code MCP server “gateway-static” wants to open a URL Please login to this URL for authorization. │ https://bedrock-agentcore.ap-northeast-1.amazonaws.com/ │ identities/oauth2/authorize?request_uri=urn%3Aietf%3A... ❯ Accept Decline
ダイアログ ② ポータルで Connect MCP server “gateway-frank” wants to open a URL ③ 再試行で成功 Called gateway-frank {"sub":"0794eac8-…", "email": "frank.resource @example.com", "username": "frank-resource"} Consent is required. Open the consent portal … │ https://<gatewayId> │ .consent-portal… ❯ Accept Decline MCP の版 同意の後の一手 2025-11-25 待機画面で Retry now を押す 2026-07-28 もう一度出るダイアログで Accept(すぐ再試行される)