CydentiCydenti
Cydenti Platform

MCP Security

Every MCP server is an identity. Who owns it. What it can reach. Whether it holds access that should stay split.

MCP server cube at the centre, linked to an agent fingerprint, a key, a chip, and a human owner, with a risk glow.
Cube = MCP server. Fingerprint = agent. Key and chip = credentials. People = owner. Red glow = risk.

What is MCP security?

The Model Context Protocol, published by Anthropic in November 2024, is how many AI agents talk to tools. An MCP server wraps GitHub, a CRM, Slack, a drive. It authenticates with its own key. That key is a non-human identity.

MCP security, here, is not prompt scanning. It is identity visibility: which servers exist, who owns them, what they can read and write, and whether one agent is stacking conflicting duties.

Cydenti is not an MCP gateway. Read-only discovery. Cutting access stays in your IAM.

Visibility, then an owner, then segregation of duties

IAM already does this for people. MCP servers skip the queue.

See

A live inventory of MCP servers and the credentials they carry. Not a config file left on a laptop.

Own

Every MCP server gets a named human owner. If that person has left, a backup is visible.

Separate duties

One agent should not stack MCP servers that conflict. Tickets on one side. Production code on the other.

A key in a JSON file,
invisible to IAM.

A developer adds a local MCP server for GitHub. Then another for the CRM. The agent answers tickets and pushes code. Nobody named an owner. No segregation-of-duties review.

Non-human identities already outnumber people 45 to 1. MCP adds credentials every week, often outside the directory.

“If the agent is trustworthy, the MCP server can still be the hole. It is the server's credential that opens the door.”

What IAM does not see
Typical MCP servers
  • A named human owner
  • A segregation-of-duties check
  • A rotation date on the key
  • Offboarding when the project dies

How Cydenti makes MCP visible

Read-only discovery, in 27 minutes, with no agent to install.

MCP inventory

MCP servers often go in with one config line. Security never sees them. Cydenti discovers them through the read-only API, the same way it finds service accounts.

Credential behind the server

The risk is not the protocol. It is the API key, OAuth token, or service account the server uses to talk to the CRM, GitHub, or Slack.

Human owner

An MCP server with no owner is an orphaned account. Cydenti names the human. The field exists. It is no longer a Slack rumour.

Segregation of duties

A support copilot that also holds an MCP server into the code repo is stacking duties. Cydenti flags it. You revoke in IAM.

Actual scope

Cydenti maps what each MCP credential can read and write. Not only the server name in a JSON file.

Tied to the agent

The server does not live alone. Cydenti ties it to the agent that uses it, in the same graph as your other NHIs.

Illustrative example

One local MCP server, two jobs

An agent named support-copilot has a HubSpot MCP server and a GitHub MCP server on a developer's laptop. It answers tickets. It can also push code. Nobody is named as owner.

Cydenti flags the segregation-of-duties conflict, shows both credentials, and the nearest human. Cutting access stays in your IAM. We do not sit in the MCP session.

FAQ

What is MCP security?

MCP security is identity work. The Model Context Protocol is how many AI agents connect to tools and data. Each MCP server carries its own credential. Security means knowing which servers exist, who owns them, what they can reach, and whether one agent holds conflicting duties across those connections.

Is an MCP server a non-human identity?

Yes. An MCP server authenticates with an API key, OAuth token, or service account. That credential is a non-human identity, same class as a service account. It does not log in with MFA. It often skips offboarding. Cydenti inventories it next to your other machine identities.

Does Cydenti replace an MCP gateway?

No. A gateway sits in the session and can mint short-lived tokens. Cydenti does not. Discovery is read-only. We show the server, the credential, the agent, and the owner. You cut or rotate access in IAM or PAM.

How do you get visibility on MCP servers?

Through the same read-only SaaS connectors as the rest of Cydenti. No agent to install. You get a live inventory of MCP servers tied to agents, plus a named human owner and the permissions on each credential.

What is segregation of duties for MCP?

One agent should not hold MCP connections that conflict: tickets plus source code, or CRM export plus production admin. Cydenti flags those combinations. IAM still decides what to revoke.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

MCP Security: credentials, owners, SoD | Cydenti