Home / Companies / Kong / Blog / Post Details
Content Deep Dive

Model Context Protocol (MCP) Security: How to Restrict Tool Access Using AI Gateways

Blog post from Kong

Post Details
Company
Date Published
Author
Deepak Grewal
Word Count
1,871
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Model Context Protocol (MCP) has traditionally allowed AI agents unrestricted access to all tools on an MCP server, which, while useful for experimentation, poses significant security and efficiency challenges in production environments. This unrestricted access can lead to over-permissioned agents, increasing security risks, and a phenomenon called "Context Rot," where an abundance of tools degrades an AI's ability to select the appropriate tool effectively. To address these issues, the text proposes a gateway-level solution that filters tools through Access Control Lists (ACLs), ensuring agents only have access to the tools they need. This method employs a progressive security model with features such as default-deny policies, role-based access, and credential isolation, leveraging tools like Kong AI Gateway for centralized control and management. This approach not only enhances security by limiting tool exposure but also improves performance by reducing unnecessary context load, ultimately streamlining AI agent operations in complex environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 49 3,346 363 139 +19%
AI Agents 9 3,583 743 199 -1%
Platform Engineering 5 368 138 58 +24%
Secrets Management 5 1,388 209 84 +19%
LLM 4 5,138 781 181 +34%
Real-time 1 5,046 1,089 214 +11%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.