Skip to content

MCP security model

The MCP bridge does not make the AI client an administrator. Every call is still evaluated against the authenticated Hyperlake identity and the target’s policy.

  • Authenticate the CLI before starting the MCP server.
  • Keep credentials in the CLI’s local credential store or environment-based secret manager.
  • Never put a token in an MCP tool argument unless a specific command explicitly requires a reference.
  • Never expose secret values in tool descriptions, logs, prompts, or returned resource listings.
  • Use credential IDs or references when an operation needs a stored credential.

For data queries, the client may receive results from the authorized target path. The control plane brokers authorization and scoped access; it is not assumed to proxy all query rows through the Rails application.

Operations return status, identifiers, policy decisions, and artifact references where applicable. A presigned download URL is time-limited. Treat it as sensitive even though it is not the underlying long-lived credential.