categories
Model Context Protocol (MCP)
Browse Pomerium articles in the Model Context Protocol (MCP) category.
Topic archive
Resources Categorized: Model Context Protocol (MCP)

Data-Layer Proxy vs Context-Aware Proxy: Which Do You Need?
Two proxy architectures secure AI agent access, and they solve different problems. How data-layer and context-aware proxies differ, and when you need each.

MCP Governance: What the OWASP Framework Requires, and Where Enforcement Has to Live
The OWASP MCP Governance & Risk Framework v1.0 sets tiers, hard gates, and audit rules for AI agents. Here's what it requires and how to enforce it at runtime.

Your IAM Was Built for People. Your Biggest Identity Problem Isn't People Anymore.
Every enterprise identity program was designed around a simple assumption: the thing logging in is a person. A person with a password, an MFA device, a predictable workday, and a manager who approves their access.

Agents Have Boundary Issues. Your Infrastructure Shouldn't.
Why the five isolation boundaries in agent security research all point to the same conclusion: enforcement has to live outside the model.

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."
.png.BOyLwQ5r.webp)
When the Web Becomes the Attacker: AI Agent Traps and the Case for Identity-Aware Access
As autonomous AI agents fan out across the open web to read pages, call tools, and drive workflows on our behalf, the web itself becomes the attack surface. The adversary no longer needs to compromise the model, the endpoint, or the user. They only need to shape the information the agent sees. The DeepMind team calls this new class of adversarial content AI Agent Traps , and their paper is the first systematic taxonomy of them.
.png.D1dxPUm2.webp)
Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026
The explosive growth of agentic AI has created a new security frontier. As large language models (LLMs) gain the ability to call external tools—through the Model Context Protocol (MCP)—organizations face an urgent question: How do you control what tools an agent can access, what parameters it can pass, and how do you audit its actions?
.png.C8TvzZ8b.webp)
MCP Server Security Risks: What Development Teams Need to Know in 2026
MCP servers give AI agents direct access to your internal systems—databases, APIs, file systems—through a standardized protocol. That's powerful for building agentic workflows, but it also creates attack vectors that traditional security tools weren't designed to handle. Gartner predicts 25% of enterprise breaches by 2028 will trace back to AI agent abuse.

What Is an Agentic Gateway? Definition, Architecture, and Why It's Different from an API Gateway
Discover what agentic gateways are, how they secure autonomous AI agents with tool-level authorization and session-aware policy enforcement, and why API gateways fall short.
MCP Apps Are Here. Is Yours Secure on Day One?
It all started with MCP-UI , then ChatGPT apps launched last October . Recently MCP apps became part of the Model Context Protocol (MCP) spec ( SEP-1865 ). Now Claude supports MCP apps. VS Code and Goose ship with MCP app support as well. MCP went from "interesting experiment" to production infrastructure in just over a year. That's faster than anything I've seen in recent memory.

MCP Security: Why MCP Is an Authorization Crisis
A developer asks an internal AI assistant to summarize a customer support ticket and check whether a refund has already been issued. The agent retrieves the ticket, queries a billing API, updates the CRM, and returns a clean summary. Everything works exactly as designed.

Hosted Clusters in Pomerium Zero & MCP Hacking (endpoints from localhost via ssh)
If you’re building an MCP server and you want a public model (ChatGPT, Claude, or Gemini) to actually call it, you hit the same wall: All the frontier models need a public HTTPS URL.
September 2025 MCP Round‑Up: Growing Adoption Meets Rising Security Fears
September was a month of contrasts for the Model Context Protocol (MCP). On the one hand, the ecosystem matured rapidly. On the other hand, a wave of reports underscored how quickly attackers are targeting these interfaces. Researchers warned of prompt‑injection attacks, backdoored packages and a raft of newly ranked vulnerabilities, while practitioners called for stronger identity flows, fine‑grained authorization and tighter governance.
August 2025 Agentic Access and MCP Content Round‑Up: Security, Innovations & Growth
August was filled with vulnerabilities and developments in the agentic AI and Model Context Protocol (MCP) landscape. Multiple high‑severity remote‑code‑execution vulnerabilities demonstrated how easily malicious servers or modified configurations can hijack developer machines. Docker went so far as to label the MCP ecosystem a “security nightmare,” prompting calls for OAuth 2.1 authorization and zero‑trust practices. Meanwhile, vendors made notable releases and thought leaders explored the future of AI as adoption accelerates.
Why Traditional Access Controls Fail in LLM Deployments
TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.
July 2025 Agentic Access and MCP Content Round‑Up: Vulnerabilities, Governance & Growth
A number of pivotal developments marked the agentic AI and Model Context Protocol (MCP) world this past July. Two critical remote‑code‑execution flaws, one in the widely used mcp‑remote tool and another in Anthropic’s MCP Inspector , highlighted the growing security risks of AI‑agent tooling. Meanwhile, vendors released new MCP servers and training programs, and the open‑source project announced a formal governance model to sustain its rapid growth. The compiled July headlines below capture both the promise and the perils of the evolving MCP ecosystem.
Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.
Top 10 Articles in Agentic Access - MCP, Models, and Clients (June 2025)
June was a messy, revealing, and incredibly important month for anyone paying attention to how AI agents interact with real-world systems.
June 2025 MCP Content Round-Up: Incidents, Updates, Releases, and more!
It’s been a busy month in the world of Model Context Protocol (MCP). Between new open source server releases, security leaks, and insightful commentary from developers building on top of these tools, there’s a lot to keep up with—and even more to think about if you're working on or around AI agents. But, one thing is clear: MCP is here, and it needs to be secured .
Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.
Asana's AI Connector Leak Exposed Sensitive Data Across Organizations: What It Means for MCP Security
When news broke that Asana's MCP server had exposed sensitive data across organizations, it wasn’t just a one-off flaw. It was a warning shot for anyone integrating AI agents into their systems without guardrails.
Secure Access for Model Context Protocol (MCP)
Learn why OAuth alone can't secure the Model Context Protocol (MCP). Discover how Pomerium enforces Zero Trust for agentic AI with per-request authorization, JWT identity, and full audit logging.
Best Model Context Protocol (MCP) Servers in 2025
The Model Context Protocol (MCP) is an open standard that connects Large Language Models (LLMs) to real-world tools and data. While static chatbots like ChatGPT and Claude can summarize and respond, autonomous agents need more—they need structured, real-time context.
Agentic Access Management for Model Context Protocol (MCP) Workflows
We’re no longer designing systems where humans are the sole decision-makers. Agentic AI changes the rules. LLMs don’t just respond to prompts anymore, they make decisions autonomously within your systems.
