Known routes
Register each protected MCP server as a route.
Control agentic sprawl
Manage MCP servers as Pomerium routes. Assign user or service-account identities, apply route policy, and limit named MCP tools.
Register each protected MCP server as a route.
Give every caller a user or service identity.
Limit exact tool names and patterns.
Route inventory
Treat each MCP server as a Pomerium route. Organize route policy in the control plane for the selected edition.
Governance boundary
Give each caller a known identity, then limit the named tools that identity can call. This boundary does not filter application records or response fields.
Protect and organize MCP server routes.
Block exact tool names, patterns, or all but an allowlist.
Manage a separate upstream OAuth connection for each user.