Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Stateless MCP and NHI credentials: what changes for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: MCP’s July 28 revision removes sessions and the initialization handshake, making each request rely on the credential it carries and turning identity governance into the central control point, according to Oasis Security. That shift exposes the assumption that session context can safely carry accountability, but stateless requests now force teams to govern the non-human identity itself.

NHIMG editorial — based on content published by Oasis Security: Stateless MCP is Simpler, Identity is More Complex Than Ever

By the numbers:

Questions worth separating out

Q: How should security teams govern MCP requests without relying on session state?

A: Treat each MCP request as a standalone identity event.

Q: Why do MCP servers increase NHI governance risk?

A: MCP servers expose tools to AI clients, which turns each request into a machine identity decision.

Q: What breaks when teams assume MCP session context will preserve accountability?

A: Accountability breaks when the protocol no longer remembers the session, because attribution, purpose, and scope can no longer be inferred from connection history.

Practitioner guidance

  • Inventory every MCP-exposed non-human identity Build a complete register of agent credentials, service accounts, API keys, and tokens that can reach MCP servers, then assign an explicit human owner for each one.
  • Rebase authorisation on token scope, not request history Review whether current policies still depend on session continuity, sticky routing, or conversation memory.
  • Enforce fast revocation at fleet scale Test revocation across all MCP-serving instances, not just a single gateway, because any node may handle the next request.

What's in the full article

Oasis Security's full blog covers the operational detail this post intentionally leaves for the source:

  • The protocol changes behind stateless MCP, including the removal of session and handshake state.
  • The identity primitives used for credential re-minting across trust domains, including actor claims and token exchange.
  • The way Enterprise-Managed Authorization works across approved servers and policy administration.
  • The operational detail behind the protocol and identity split that implementation teams will need before rollout.

👉 Read Oasis Security's analysis of stateless MCP and NHI governance →

Stateless MCP and NHI credentials: what changes for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Stateless protocol design creates an identity governance event, not just an MCP engineering update. The moment session memory disappears, every control that depended on connection continuity becomes weaker or irrelevant. That does not mean MCP is less secure by default. It means identity governance must now carry the burden that the protocol used to mask, and the practitioner conclusion is simple: govern the credential, not the connection.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
  • Only 71% of NHIs are not rotated within recommended time frames, which leaves standing credentials exposed long after the task that created them has ended.

A question worth separating out:

Q: Who is responsible for revoking over-scoped MCP credentials?

A: The owning security and identity function must treat MCP credentials like any other governed NHI asset. That means explicit ownership, fast revocation, and lifecycle review. If revocation depends on a transport session ending, the control is already too weak for stateless requests.

👉 Read our full editorial: Stateless MCP shifts accountability to NHI credentials and policy



   
ReplyQuote
Share: