CydentiCydenti
NHI Glossary

What Is MCP (Model Context Protocol)?

The Model Context Protocol (MCP) is an open standard, introduced by Anthropic in November 2024, that defines how AI applications — such as large language model (LLM) assistants and autonomous agents — connect to external tools, data sources, and services. Rather than building a custom integration for every API or database an AI agent needs to reach, MCP provides a common client-server interface: an MCP client (the AI application) sends requests to an MCP server, which exposes a defined set of tools, resources, or prompts. MCP servers commonly wrap systems like file storage, ticketing platforms, code repositories, CRMs, or cloud APIs. Because each MCP server typically authenticates using its own credential — an API key, OAuth token, or service account — MCP has effectively become a new, fast-growing category of non-human identity (NHI) that security teams must inventory and govern.

Why It Matters

MCP servers and clients don't authenticate themselves the way a human logs in — they carry standing credentials: API keys, OAuth tokens, or embedded secrets that grant the agent broad, often unreviewed access to connected systems. An AI agent wired to five MCP servers effectively holds five separate non-human identities, each with its own permissions, and each one is a potential path for a compromised or manipulated agent to reach production data, source code, or customer records. Because MCP adoption is moving faster than identity governance, these credentials are frequently over-scoped, long-lived, and invisible to traditional IAM and PAM tools built for human and simple service accounts. OWASP's NHI Top 10 (2025) found that 80% of identity breaches now involve a non-human identity, and organizations already run non-human identities that can outnumber employees 45 to 1 — MCP integrations add to that count daily. Under NIS2 (enforcement from October 1, 2026) and ANSSI's ReCyF Objective 13, these machine credentials fall squarely within scope for service-account and technical-account governance, making unmanaged MCP connections a compliance gap as much as a security one.

How Cydenti Helps

Cydenti discovers every MCP server credential connected to your AI agents — API keys, OAuth tokens, and service accounts alike — and maps them into your broader non-human identity inventory, alongside the agents and systems they touch. Instead of treating each MCP connection as an isolated integration, Cydenti shows the full identity graph: which agent holds which credential, what scope it was granted, whether it's still in use, and what it can reach if compromised. That visibility lets security teams apply least-privilege reviews and rotation policies to MCP credentials the same way they already do for traditional service accounts, closing the gap before an unmanaged connection becomes an incident.

Explore →

Frequently Asked Questions

Is MCP the same as an API?

Not quite. MCP is a standardized protocol that sits on top of APIs, giving AI agents a consistent way to discover and call tools across many different systems, instead of requiring a custom integration for each API. Each MCP server still typically calls underlying APIs using its own credentials, which is why MCP connections need the same identity governance as any other machine credential.

Who created MCP and is it widely adopted?

Anthropic introduced MCP as an open standard in November 2024. It has since been adopted across the AI ecosystem, with major AI vendors, developer tools, and enterprise platforms building or supporting MCP servers, making it a de facto standard for connecting AI agents to external systems and data.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

What Is MCP (Model Context Protocol)? | Cydenti