{"slug": "how-are-you-authorizing-ai-agents-that-call-mcp-servers", "title": "How are you authorizing AI agents that call MCP servers?", "summary": "Keydris has launched a trust infrastructure for AI agents that call MCP servers, centered on a Gateway that issues scoped, signed KIT tokens verified by lightweight Kit Reader middleware before any tool call reaches the server. The system provides an append-only, hash-chained audit log and machine-speed revocation across boundaries, designed to meet the standards of CISOs, platform engineers, and compliance leads.", "body_md": "Trust Infrastructure for the autonomous economy -\n\nTrust Infrastructure for the autonomous economy -\n\nEVERY ACTION, CHECKED\n\nThe Keydris Gateway sits at the heart of the flow: it issues each agent a kit, scoped by the policies you set in the Keydris app. Agents present that kit with every tool call, and the Kit Reader : lightweight middleware installed on top of your MCP server : checks it with the gateway and allows or denies the call before it ever reaches the server.\n\nVerified agent\n\nKit Reader\n\ndoorstep access control\n\nMCP Server\n\ntools & data\n\nUnverified agent\n\nKeydris Gateway\n\nissues agent kits\n\nKeydris App\n\nset policies\n\nWHY THIS EXISTS\n\nThe standard of proof\n\nArchetypal roles, not customer quotes — the standard Keydris is built to meet.\n\n“Which of these actions was actually authorized , and by whom?”\n\nChief information security officer\n\nEvery action arrives with its permission attached: issuer, scope, policy, signature , verifiable in milliseconds, independent of the agent that carried it.\n\nissuer acme-corp.keydris.id · sig valid\n\n“If we revoke an agent's authority at 09:00, what does it prove at 09:01?”\n\nHead of platform engineering\n\nNothing. Revocation is part of verification itself — the next check fails, and the audit trail shows exactly when.\n\n09:00:00Z · authority revoked\n\n09:00:03Z · revocation feed synced\n\n09:00:41Z · action attempted → refused · record signed\n\n“Show me the record you would hand an auditor.”\n\nCompliance lead\n\nA signed sequence of decisions, handed over as it stands: each record names the request, the policy in force, the checks, and the outcome.\n\nrecord kd_evt_29fa… · signed\n\nTHE KIT\n\nAnd the layer stays neutral. Keydris is independent of any model, vendor, platform, or rail. A requirement for infrastructure that sits between institutions rather than inside one of them.\n\nSigned KIT token\n\n•\n\nScoped permissions\n\n•\n\nMinimum privilege\n\nKeydris issues the agent a signed token, the KIT. It states what the agent may do and for how long. Minimum privilege by default.\n\nAppend-only log\n\n•\n\nHash-chained\n\n•\n\nImmutable record\n\nThe authorization is bound to an append-only, hash-chained log. An immutable record of what the agent was permitted to do.\n\nEnforced at the front door\n\n•\n\nProof checked first\n\n•\n\nNo proof, no connection\n\nEnforcement is at the counterparty's front door. The receiving system verifies the token before the agent can connect or act.\n\nMachine-speed revocation\n\n•\n\nAcross every boundary\n\n•\n\nFails verification instantly\n\nAuthority is pulled at machine speed, across every boundary. A revoked token fails verification the instant permission should end.", "url": "https://wpnews.pro/news/how-are-you-authorizing-ai-agents-that-call-mcp-servers", "canonical_source": "https://www.keydris.com/", "published_at": "2026-07-25 19:57:56+00:00", "updated_at": "2026-07-25 20:22:45.239720+00:00", "lang": "en", "topics": ["ai-agents", "ai-infrastructure", "ai-safety", "ai-policy"], "entities": ["Keydris", "Keydris Gateway", "Keydris App", "Kit Reader", "MCP Server"], "alternates": {"html": "https://wpnews.pro/news/how-are-you-authorizing-ai-agents-that-call-mcp-servers", "markdown": "https://wpnews.pro/news/how-are-you-authorizing-ai-agents-that-call-mcp-servers.md", "text": "https://wpnews.pro/news/how-are-you-authorizing-ai-agents-that-call-mcp-servers.txt", "jsonld": "https://wpnews.pro/news/how-are-you-authorizing-ai-agents-that-call-mcp-servers.jsonld"}}