TL;DR: Teleport’s analysis says MCP is becoming the standard path for AI agents to reach enterprise data, but static credentials, weak session controls, and limited auditability leave material governance gaps. The core problem is that agentic access behaves like identity delegation, so existing IAM assumptions break quickly.
At a glance
What this is: This is a Teleport analysis of securing Model Context Protocol for agentic AI, arguing that MCP turns AI access into an identity governance problem because static credentials, weak session control, and poor auditability do not scale.
Why it matters: IAM, PAM, and NHI teams need to treat MCP-backed AI access as governed identity delegation, or agent-driven data access will outrun existing lifecycle, logging, and revocation controls.
👉 Read Teleport's analysis of MCP identity governance for agentic AI access
Context
MCP is a standard way for AI systems and agents to connect to enterprise data sources, APIs, and services. In practice, that makes the protocol part of the identity stack, because the real question is no longer whether an AI can call a tool, but what it is allowed to reach and how that access is governed.
Teleport’s analysis argues that the gap is not connectivity but control. Once AI agents act on behalf of users through MCP, organizations need least privilege, session boundaries, attribution, and revocation models that are strong enough for machine-driven access and auditable enough for regulated environments.
Key questions
Q: What breaks when MCP servers rely on a single shared credential?
A: A single shared credential breaks attribution, scope control, and revocation precision. If the server can be used by multiple people, you cannot easily tell which human authorised a specific action, and removing the credential can disrupt unrelated workflows. That makes the credential both operationally convenient and governance-heavy.
Q: Why do MCP-connected agents increase AI data leakage risk?
A: MCP-connected agents can retrieve data directly from enterprise systems, so sensitive information may enter AI workflows without a person copying it into a prompt. That creates a delegated retrieval path, which expands the attack and compliance surface. Organisations need policy controls on what the agent may retrieve and what may be passed onward to the model.
Q: How can organisations tell whether MCP access is actually being governed?
A: A governed MCP deployment can answer who requested access, what scope was granted, when the token expires, and which tool calls were made under that token. If logs only show a shared credential or generic server activity, the organisation does not have effective identity governance for the protocol.
Q: Should organisations treat MCP connectors like ordinary integrations?
A: No. MCP connectors often carry delegated access into multiple tools and data stores, which makes them part of the identity control plane. They should be registered, scoped, monitored, and offboarded like any other privileged machine identity, otherwise a compromise in one connector can expand into broader system access.
Technical breakdown
Static credentials create standing access for MCP servers
MCP deployments often rely on API keys, database passwords, or service account credentials that persist beyond the task they support. That creates standing access, which is manageable for stable workloads but weak for AI systems that can change behaviour, context, and target data during a session. The protocol may standardise connectivity, but it does not itself solve lifecycle governance, revocation, or privilege scoping. In an identity model, the important issue is not just authentication at connection time but how long that trust remains valid and how narrowly it is constrained.
Practical implication: replace persistent secrets with issued, task-scoped credentials and treat MCP servers as governed identities rather than integration endpoints.
Why auditability fails when AI access lacks session controls
Traditional audit models assume there is a clear actor, a stable session, and an attributable action trail. MCP weakens all three if the surrounding controls are thin, because an AI agent can request broad access, call multiple resources, and continue operating with little human visibility. Without granular logging tied to the agent identity, resource, and action, incident response becomes forensic guesswork rather than traceable investigation. That is a governance failure as much as a technical one, because compliance controls depend on evidence of who accessed what and why.
Practical implication: bind logs to AI identity, resource scope, and session context so security teams can reconstruct access without relying on application logs alone.
MCP inherits the trust boundaries of the broader AI supply chain
MCP does not live in isolation. It sits between the model, the agent framework, the connector, and the downstream data source, so any weakness in the surrounding chain can expand the blast radius. Teleport’s framing maps to a familiar pattern in NHI security: the connector becomes the credentialed bridge between trust domains, which means over-privilege or weak authentication at that bridge can expose everything behind it. The architectural lesson is that protocol standardisation does not equal governance standardisation.
Practical implication: review every MCP connector as part of the AI access chain and apply the same trust-boundary analysis used for privileged service accounts.
Threat narrative
Attacker objective: The objective is to turn trusted AI connectivity into unauthorized access to enterprise data and downstream systems.
- Entry begins when an AI system or MCP server uses static credentials or API keys to connect to enterprise resources with broad trust.
- Escalation occurs when the agent is allowed to request wider data access or continue across tasks without strong session scoping or revocation controls.
- Impact follows when those credentials or access paths are abused to expose sensitive data, trigger unauthorized actions, or frustrate incident response because attribution is incomplete.
Breaches seen in the wild
- LiteLLM MCP auth bypass 2026: An exploited LiteLLM MCP auth bypass and default sk-1234 master keys let attackers steal AI gateway master and provider API keys.
- AI LLM hijack breach: attackers used stolen AWS access keys to hijack Anthropic LLM models on Bedrock.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
MCP has become an identity governance problem before it becomes an application integration problem. Once AI systems act on behalf of users through MCP, the decisive question is not transport but authorization, attribution, and revocation. That shifts the control plane from integration engineering to identity governance, because the connector now mediates access to sensitive data and business processes. Practitioners should treat every MCP path as governed access, not convenience plumbing.
Static credentials are the wrong trust primitive for agentic access. They assume the accessing actor is stable, predictable, and reviewable over time. That assumption fails when an autonomous or semi-autonomous agent can change its tool usage and data needs during runtime. The implication is that credential issuance and scope definition must move closer to execution, because provisioning-time privilege no longer matches runtime behaviour.
Auditability is the missing proof layer in AI access governance. Traditional logs often show that a connector was used, but not enough to prove which AI identity accessed which resource for which task. That leaves compliance, incident response, and recertification operating on partial evidence. The practical conclusion is that MCP governance must produce an attributable record of access, not just a connection event.
Ephemeral credential trust debt: AI infrastructure inherits the same hidden debt seen in NHI estates when short-lived access is not matched by short-lived governance. Temporary tokens reduce exposure, but they do not by themselves create policy clarity, session context, or ownership. Practitioners should read MCP adoption as a signal that identity lifecycle controls now have to cover AI connectors as first-class workloads.
Agentic AI turns least privilege into a runtime discipline, not a provisioning exercise. A model or agent can follow different paths for different prompts, so effective privilege must be defined against task scope and session context rather than static role assumptions. That is why conventional IAM reviews understate the real risk. Teams should govern the action path, not just the account that enables it.
From our research library:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
- Read next: AI Infrastructure Workload Identity Guide
What this signals
Agentic access will force IAM teams to move controls from connection setup to access issuance. The old model assumes a connector can be trusted once authenticated, but MCP-backed AI systems can change intent and scope mid-workflow. That means privilege needs to be judged at the point of execution, not just at onboarding.
Ephemeral access only helps when governance is equally ephemeral. Temporary tokens reduce exposure, but they do not solve ownership, attribution, or review if the surrounding controls still assume a stable human operator. In practice, AI access programmes need issuance, logging, and revocation to move as one control surface.
For practitioners
- Replace standing secrets with scoped issuance Issue short-lived credentials to MCP servers and AI agents, and bind them to narrow resource and task scopes instead of persistent repository-stored secrets.
- Bind audit trails to AI identity Log the agent identity, resource accessed, action performed, and session context so investigations can reconstruct AI-driven access without relying on indirect evidence.
- Review every connector as a trust boundary Classify each MCP integration as a privileged access path and assess whether the downstream data source would be exposed if the connector were over-privileged or compromised.
- Scope access to task intent Map specific agent tasks to minimum required resources and revoke anything that is not explicitly needed for the current business function.
- Align incident response to AI access revocation Predefine how to disable MCP access, revoke issued tokens, and preserve evidence when an AI connector or agent behaves outside its approved scope.
Key takeaways
- MCP-backed AI access is really a governance problem about who or what may reach enterprise data, not just a protocol integration issue.
- Static credentials, weak session controls, and incomplete audit trails are the three gaps that make agentic access hard to contain.
- Teams that want to use MCP safely need to govern AI identities with the same discipline they apply to privileged non-human access.
Key terms
- Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
- Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions, including calling APIs, writing code, and orchestrating other agents, with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
- Ephemeral Credentials: Ephemeral credentials are short-lived access artefacts issued for a limited task or session. They reduce the window for abuse, but they only improve security when paired with strong scope limits, telemetry, and automatic revocation at task completion.
- Identity Delegation Drift: Identity delegation drift is the gradual expansion of permissions originally granted for a narrow workflow into broader, persistent access. It often appears in automation and AI tooling where convenience overrides review, leaving organisations with standing trust they no longer understand or need.
What's in the full article
Teleport's full blog post covers the operational detail this post intentionally leaves for the source:
- Teleport’s identity platform architecture for AI infrastructure and MCP servers
- How ephemeral credentials are issued and scoped for AI-driven database access
- The implementation roadmap for audit logging, revocation, and zero trust controls
- Business impact examples for regulated environments adopting agentic AI
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org