Solutions

Zero-trust architecture for tools, resources, and secrets

ForgeCrux MCP Security puts every Model Context Protocol call on a governed path: authenticate the client, authorize the tool, inject vaulted credentials, inspect payloads, rate-limit, and write an immutable audit record.

deny

by default

Unlisted tools and servers are invisible to the client.

0

long-lived secrets in agents

JIT injection and rotation at the gateway.

arg

level authorization

Policies can constrain project, account, and path.

100%

calls audited

Discovery and invocation share one evidence store.

Enterprise architecture

Zero-trust MCP security path

Every tool discovery and invocation is authenticated, authorized, vault-injected, inspected, and audited—default deny.

Zero-trust MCP security path

ForgeCruxProbing Deeper, Stacking Precision

MCP clients

IDE, agents, apps

Identity

OIDC, mTLS, SCIM

MCP Gateway

Virtual catalog · arg-level RBAC · DLP · vault JIT · HITL · sandbox egress

Tool backends

SaaS, data, internal

SIEM / WORM

100% call audit

Default deny

Unlisted tools invisible

Secrets never in agents

Vault lease per call

Mutating tools

HITL until evals pass

Tools are production APIs

The same discipline you apply to northbound APIs applies to every agent tool call.

Secrets stay in the vault

Models and agents never hold raw database, SaaS, or cloud keys.

Forensics in minutes

Security can answer who invoked which tool, with which args, under which policy version.

Key Capabilities

Zero-trust default deny on all MCP tools
OAuth 2.0 / OIDC / mTLS for MCP clients
Tool- and argument-level RBAC/ABAC
Credential vault with just-in-time injection
Virtual catalogs that hide unauthorized tools
DLP and PII redaction on arguments and results
Egress allow lists and sandboxing
Human approval for mutating or privileged tools
Rate limits, quotas, and circuit breakers
Full audit of list, read, subscribe, and call
Anomaly detection on unusual tool sequences
Air-gapped and VPC-only MCP data planes

Complete MCP Security capabilities

Everything required to publish, secure, mediate, observe, and operate mcp security workloads on ForgeCrux.

Enterprise uses

Who needs zero-trust MCP and what they block.

  • Security: default-deny tools, DLP on args/results, SIEM evidence
  • Platform: one virtual catalog per team instead of sprawl of stdio servers
  • Developers: IDE MCP clients that never hold SaaS or DB keys
  • Agent operations: mutating production tools behind HITL
  • GRC: recertify who can call which tool under which policy version
  • SRE: rate limits, circuit breakers, and session revoke on abuse

Installation & deployment

Put the gateway in front of every MCP server.

  • MCP Gateway data plane in SaaS, VPC, Kubernetes, or air-gapped
  • Vault / KMS for JIT credential injection
  • OIDC, mTLS, and SCIM for clients and operators
  • Network egress allow lists and DNS policy at the sandbox
  • Environment isolation so dev catalogs cannot reach prod servers
  • WORM audit store and SIEM correlation IDs

Setup & onboarding

Inventory, vault, virtualize, then enforce.

  • List stdio and remote MCP servers used by IDEs and agents
  • Move secrets out of configs into the ForgeCrux vault
  • Publish virtual catalogs—one endpoint per team
  • Point clients at the gateway; block direct server URLs
  • Enable arg-level policies and DLP on tools/call
  • HITL on mutating prod tools until red-team evals pass

Security & forensics

Authenticate, authorize, inject, inspect, audit.

  • Default deny; unlisted tools are invisible
  • Tool- and argument-level RBAC/ABAC
  • Zero long-lived secrets in agents
  • Prompt-injection defenses on tool descriptions and results
  • Sequence anomaly detection and automatic agent pause
  • 100% audit of list, read, subscribe, and call

Prevent

Stop unauthorized and unsafe tool use before it happens.

  • Default-deny catalogs and tool aliases
  • Parameter constraints and schema validation
  • Network egress and DNS allow lists
  • Prompt-injection defenses on tool descriptions and results
  • Environment isolation (dev tools cannot hit prod)
  • Device and workload posture checks

Detect and respond

See abuse quickly and contain it.

  • Sequence anomalies (recon then exfil patterns)
  • Volume and off-hours detections
  • Automatic session revoke and agent pause
  • SOAR webhooks and SIEM correlation IDs
  • Forensic export of call payloads under legal hold
  • Tabletop and red-team MCP scenarios

Data flows

How requests, policies, and telemetry move through ForgeCrux in this solution.

Authorized tool invocation

Standard call with vaulted credentials.

1

tools/call

JSON-RPC

2

AuthN/Z

Token + policy

3

Inject secret

Vault lease

4

Backend

Scoped action

5

Redact + log

Result to client

Blocked or approved path

When policy denies or requires a human.

1

Sensitive tool

e.g. prod write

2

PDP deny/queue

Risk tier

3

HITL

Owner decision

4

Execute or reject

Ticketed

5

Audit

Who approved

How teams run MCP Security on ForgeCrux

Inventory MCP servers

List stdio and remote servers in use by IDEs and agents.

Move secrets

Strip keys from configs; register them in the ForgeCrux vault.

Publish virtual catalogs

One endpoint per team with only their tools.

Enforce in path

Point clients at the gateway; block direct server URLs.

Turn on HITL

Mutating production tools require approval until evals pass.

Prove it

Feed audit to SIEM and run an access recertification.

Ready to get started with MCP Security?

Talk to our team about deploying MCP Security in your enterprise environment.