How to Secure an MCP Server: 10 Steps
How to secure an MCP server in ten ordered steps: scope credentials, authenticate callers, bound parameters, contain injection, log every call and verify it works.
Read the guide →Archive
How to secure an MCP server in ten ordered steps: scope credentials, authenticate callers, bound parameters, contain injection, log every call and verify it works.
Read the guide →How to let AI agents pay without granting unlimited authority: the six bounds every payment-capable agent needs, approval that stays useful, duplicate-payment prevention, and the eight-field payment record.
Read the guide →How tool descriptions become an instruction channel: four poisoning variants, six adversarial review questions, what to diff on every upgrade, and how to contain a server you cannot audit.
Read the guide →How prompt injection reaches tools through MCP: four injection paths, the anatomy of a working attack, five defences that do not hold, the containment that does, and how to test it in an afternoon.
Read the guide →MCP access control in practice: the four levels entitlement operates at, why RBAC alone leaves the largest gap, applying least privilege to tools and parameters, multi-tenant isolation, and a 30-day de-entitlement routine.
Read the guide →Why authentication and role-based authorization stop short for autonomous agents, what action authorization adds, how delegated authority works, and a four-stage path from roles to per-action decisions.
Read the guide →A structured threat model for Model Context Protocol: five attack surfaces, sixteen named risks with likelihood and blast radius, which controls actually mitigate each, and the three risks with no clean mitigation.
Read the guide →Eighteen MCP security practices grouped by identity, surface, policy, evidence and supply chain — each with the failure it prevents, an effort estimate, and a test that expects refusal.
Read the guide →Why build-time review misses agent risk, the five runtime control points in a single tool call, circuit breakers and kill switches, fail-closed versus fail-open by risk class, and how to test runtime controls.
Read the guide →Three different products are sold as AI agent firewalls: content firewalls, tool-call firewalls and action firewalls. What each inspects, where each sits, which threats each stops, and the four questions that reveal which one you are being shown.
Read the guide →