Skip to main content

Secure AI agent access

Select the right Pomerium pattern for agent access

Authenticate each user or service account, apply policy to every request, limit named MCP tools, and manage upstream OAuth when the server requires it.

What this pattern controls

Known agent identity

Use delegated user identity or a service account.

Route boundary

Attach policy to each protected MCP route.

Tool policy

Restrict the named tools the caller can use.

Agent identity

Choose delegated user access or a service account

Put Pomerium between MCP clients and the MCP servers they use. Define one protected route for each MCP server.

  • Use a delegated external token when an agent acts for an interactive user.
  • Use a service account JWT for a headless agent or background job.
  • Apply the route policy to the resulting identity.

MCP boundary

Limit named tools and manage upstream OAuth

Pomerium controls the request and named MCP tool call. It does not infer prompt or task intent.

  • Use mcp_tool under deny for exact names, patterns, or an allowlist.
  • Use upstream OAuth when the protected server requires a separate user connection.
  • Record the authorization decision with selected MCP fields.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo