Another interesting problem: say we use MCP. It looks like OAuth can get the user's identity to the server. What's the standard way — the zero-trust way 😏 — for the server to decide whether this user is authorized to invoke a given capability? Or even whether the server should admit to them that the capability exists?