Home / Companies / Wundergraph / Blog / Post Details
Content Deep Dive

Safelist GraphQL Operations for AI Agents | Cosmo MCP Gateway

Blog post from Wundergraph

Post Details
Company
Date Published
Author
Ahmet Soormally
Word Count
1,572
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Cosmo Router MCP Gateway enables AI agents to interact with federated GraphQL schemas by exposing them as reviewed and OAuth-scoped tools. This approach ensures that AI agents can explore schemas during development but are restricted to executing only approved operations in production. The MCP Gateway operates on a composed supergraph, allowing seamless data resolution across multiple subgraphs without requiring additional services. Two configuration flags manage its operation: one controls schema exposure and the other manages the ability for agents to execute arbitrary operations. During development, both flags are enabled to allow comprehensive schema exploration and query execution, while in production, they are disabled to restrict agents to pre-approved operations, minimizing potential security risks. The system supports per-operation authorization using OAuth 2.1, ensuring that agents operate within their permitted scopes. The architecture is designed to handle schema changes efficiently, with operations re-validated automatically upon schema updates, ensuring continued functionality without manual intervention. This setup avoids the need for a separate AI-safe API by maintaining a single source of truth, which simplifies governance and reduces infrastructure complexity.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
MCP 13 7,668 844 209 +8%
AI Agents 5 6,119 1,396 266 +24%
Developer Experience 1 404 252 100 -15%
Platform Engineering 1 1,658 258 90 +29%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.