MCP security model
The MCP bridge does not make the AI client an administrator. Every call is still evaluated against the authenticated Hyperlake identity and the target’s policy.
Credential rules
Section titled “Credential rules”- Authenticate the CLI before starting the MCP server.
- Keep credentials in the CLI’s local credential store or environment-based secret manager.
- Never put a token in an MCP tool argument unless a specific command explicitly requires a reference.
- Never expose secret values in tool descriptions, logs, prompts, or returned resource listings.
- Use credential IDs or references when an operation needs a stored credential.
Direct target execution
Section titled “Direct target execution”For data queries, the client may receive results from the authorized target path. The control plane brokers authorization and scoped access; it is not assumed to proxy all query rows through the Rails application.
Evidence
Section titled “Evidence”Operations return status, identifiers, policy decisions, and artifact references where applicable. A presigned download URL is time-limited. Treat it as sensitive even though it is not the underlying long-lived credential.