Need this for CLI tools like gcloud, knife, npm, etc. Maybe an Okta based JWT.

What's interesting about this standard is that it's not really MCP-specific. It can work just as nicely for any other workload - it just requires the authorization server/IdP to support it and the receiver to know how to handle the trust relationship.