This is the right pattern. OAuth plus scoped session keys solves the credential-sharing problem cleanly for web services, but agent-to-agent scenarios need a programmable delegation layer — the MCP server controls what each capability authorizes at the action level, not just the API scope. Combining short-lived session keys with capability-based permissions is the next step for autonomous agent pipelines.