AI Agent & MCP Security
Give every AI agent its own Keycloak identity with scoped, short-lived tokens, protect MCP servers with OAuth 2.1, and add human approval, audit trails and a tested kill switch.
Overview
Agents are often wired to APIs with a user's token or a long-lived key, which makes them invisible and impossible to limit. We give each agent its own Keycloak client and credentials, narrow scopes and audiences, and access tokens that last minutes. When an agent acts for a signed-in user, it uses Keycloak's standard token exchange to get a narrower token for a single API, so your logs show both the user and the agent. High-risk actions can require a person's approval on their own device through OpenID CIBA before a token is issued. For the Model Context Protocol, Keycloak becomes the authorization server for your MCP servers: discovery metadata, PKCE, dynamic client registration behind policies, and tokens bound to each server's audience. Where the MCP spec moves faster than Keycloak, such as resource indicators or newer client registration methods, we close the gap with configuration, a gateway or an extension, checked against your Keycloak version. Governance ties it together: an agent inventory with owners, access reviews, audit dashboards and a rehearsed kill switch.
Delivery Process
What's Included
- Agent inventory and access model
- Keycloak clients, scopes and audiences per agent
- Token exchange for delegated, on-behalf-of access
- MCP server authorization: discovery, PKCE and registration policies
- CIBA human-approval flow for high-risk actions
- Audit dashboards and emergency revocation runbook
Timeline & Scope
Timeline
3-5 weeks
Ideal For
Teams shipping AI agents, copilots or MCP servers that need least-privilege access, delegation, and evidence for security and audit reviews.
Warranty
30-day warranty covering token, delegation, MCP authorization and approval-flow issues discovered after go-live.
Tech Stack
Ready to get started?
Fixed price. Clear scope. 30-day warranty.