What's wrong with this entry?
The MCP OAuth cross-app access (XAA) system has received a major expansion with full PRM (Protected Resource Metadata) discovery, AS (Authorization Server) metadata discovery, and a two-stage token exchange flow (ID token → ID-JAG → access token). New --xaa, --client-id, and --client-secret flags are now available for MCP server configuration. A dedicated XaaTokenExchangeError class provides better error handling with per-stage failure tracking.
XAA protocol flow (search for "XAA: starting cross-app access flow") — eB1() at line ~327934
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.