The four questions Chicago wouldn’t let go
Blog post from Tyk
A Chicago LEAP on Tour discussion involving 14 participants from 12 companies identified four recurring governance challenges for Model Context Protocol (MCP) deployments: preserving both human and agent identity through token exchanges, applying conventional API security controls at every step of autonomous agent workflows, fairly managing access to shared rate-limited tools, and maintaining a comprehensive inventory of MCP servers. Participants described using narrowly scoped, exchanged tokens to retain the originating user identity while identifying the acting agent and limiting permissions for each call. They argued that MCP security largely relies on established API practices such as authentication, authorization, logging, and least-privilege scopes, but requires stronger enforcement because agents may independently chain multiple actions. Proposed approaches included per-consumer, per-tool quotas and a centralized registry connected to developer portals to address resource competition and server visibility. The discussion also highlighted an unresolved challenge: securely handling identity and authorization when work passes across multiple agents, since tokens intended for one service may not be accepted by subsequent services.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| MCP | 4 | 2,241 | 148 | 72 | -74% |
| AI Agents | 2 | 931 | 231 | 103 | -84% |
| AI Coding Assistant | 1 | 341 | 115 | 55 | -77% |
| LLM | 1 | 747 | 162 | 79 | -85% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.