Join our Newsletter — 33% off our NHI Course

MCP tool calls in 2026: what gateway controls actually matter?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: As MCP becomes the default tool-calling layer for agents, organisations need gateways that can enforce tool-level policy, short-lived identity assertions, session-aware controls, and auditable decisions. Pomerium’s analysis argues that traditional API gateways miss the semantic and governance gaps that agentic workflows create.

Editorial analysis by NHI Mgmt Group, based on content published by Pomerium: “Top 5 Agentic Gateways for Securing MCP Tool Calls in 2026”.

By the numbers:

  • 1,862 internet-exposed MCP servers with zero authentication show how quickly agentic infrastructure can outpace baseline access controls.

Key questions

Q: What breaks when MCP is governed only as generic API traffic?

A: You lose tool-level control, workflow context, and meaningful audit evidence.

Q: Why do short-lived assertions matter for agentic tool access?

A: They reduce the value of stolen credentials and align access with a specific request or session instead of a reusable secret.

Q: How do you know if an MCP gateway is actually enforcing policy?

A: Check whether it can produce an auditable decision trail that includes the agent, tool, method, parameters, and allow or deny outcome.

Practitioner guidance

  • Define tool-level entitlements Map every MCP server method to an explicit allow or deny decision, and do not rely on server-wide access as a proxy for least privilege.
  • Replace reusable agent secrets Move agents to short-lived identity assertions or equivalent ephemeral credentials so a compromised process cannot replay a standing secret.
  • Make policy session-aware Require the gateway to evaluate prior steps, user approval state, and workflow context before allowing sensitive follow-on tool calls.

Bottom line: MCP changes the security unit from server access to tool-level action control, which generic API gateways do not reliably provide.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 6 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21396
 

MCP security is now an identity governance problem, not an API management footnote. The article shows that agentic gateways are needed because MCP tool calls expose a control surface that traditional gateways were not built to understand. Tool identity, session context, and delegated actions now sit inside the trust decision, which means IAM and NHI teams have to govern the call path as well as the credential. Practitioners should treat MCP as an identity enforcement layer.

A few things that frame the scale:

  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
  • Only 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, sharing sensitive data, or revealing access credentials.

A question worth separating out:

Q: How do teams evaluate whether an agentic gateway is actually working?

A: Teams should look for three signals: tool-level denial of unsafe methods, preserved session context across multi-step workflows, and audit logs that show who or what approved each call. If the gateway only blocks whole servers or records generic traffic, it is not governing agentic behaviour at the right granularity.

👉 Read our full editorial: Top agentic gateways for securing MCP tool calls in 2026



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21396
 

Tool-level authorisation has become the control boundary for agentic identity. MCP moves the governance question from who can reach a server to what an agent can do inside that server. That is a different control plane, and teams that keep treating MCP like generic API traffic will miss the real privilege boundary. The practical conclusion is that access policy must be written at the level of tools and methods, not only endpoints.

A few things that frame the scale:

  • 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: When should teams choose a session-aware gateway over standard API management?

A: Use session-aware controls when an agent makes multi-step decisions and the safety of later calls depends on earlier approvals or workflow state. Standard API management is often enough for static request patterns. It is not enough when authorisation must follow the sequence of an autonomous or semi-autonomous task.

👉 Read our full editorial: Top agentic gateways for securing MCP tool calls in 2026


This post was modified 6 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.