Skip to main content
Feedback

Centralized user management

MCP Gateway provides centralized user, authentication, and access management for enterprise AI and agentic environments. Through a unified governance framework, organizations control who has access to which MCP servers, tools, integrations, and resources. Organizations maintain visibility and compliance as systems scale.

MCP Gateway combines IdP integration with role-based access profiles. You can plug MCP Gateway into your existing security models and identity workflows without rebuilding them.

Identity-aware MCP usage

  • Supported IdPs: Bring your own IdP. MCP Gateway supports major IdPs including Okta, Microsoft Entra (formerly Azure AD), Google Workspace, JumpCloud, Keycloak, and more. Integration aligns with your existing cloud architecture, security requirements, and organizational access policies.

  • Identity-aware access control: Every request flowing through MCP Gateway carries verified identity context. You can enforce access policies and permissions at the user, group, role, or agent level, enabling granular governance beyond static API keys or shared credentials.

For how identity context ties into system visibility and event tracking, refer to Full auditability.

Role-based access profiles

Role-based access (RBAC) profiles define reusable access structures that apply across users, agents, servers, and tools.

  • Centralized policy definition: Create reusable access profiles, such as developer, analyst, or admin, to define exactly which MCP servers and tools each role can access.

  • Scalable assignment: Assign profiles to individual users or entire groups, while your existing RBAC policies and IdP definitions continue to enforce authentication and authorization.

  • Dynamic policy enforcement: Any update to a profile is automatically propagated to all associated users and groups.

Together, IdP integration and RBAC profiles give you a single control surface for managing who can connect to what, across every layer of your MCP ecosystem.

How it works

  1. Connect your IdP. Configure MCP Gateway to authenticate users through your existing provider.
  2. Define profiles. Set up reusable role profiles with access rules for tools and servers.
  3. Assign and enforce. Apply profiles to users or agents authenticated through your IdP.
  4. Monitor usage. View connected identities and profile assignments through the MCP Gateway control plane.

Benefits

  • Unified identity and access management: Centrally manage authentication, permissions, and access policies across all MCP servers, tools, agents, and integrations.

  • Simplified onboarding and offboarding: Leverage your existing IdP workflows to automatically provision, update, and revoke access without additional operational overhead.

  • Consistent and scalable policy enforcement: Apply organization-wide access controls and governance policies consistently across every connected MCP environment.

  • Reduced configuration drift: Maintain centralized role and access definitions to minimize inconsistencies between teams, environments, and deployed MCP servers.

  • Extended OAuth compatibility: Enable OAuth-based authentication flows even for MCP servers without native OAuth support, through hosted STDIO server integrations.

On this Page