El token válido equivocado: autenticar un servidor de herramientas MCP con authentik
- 1Lock down Docker networks
- 2Run containers as non-root
- 3Identity in front of every port
- 4Membership, not just an account
- 5An identity for the agent, not a key
- 6A tool server that checks who is asking
- 7Where the agent can go, not just what it can call
- 8Move the daemon off root
- 9Run the model's own code without trusting it
- 🏆A scope per tool, and a refusal clients can act on
La Parte 5 le dio a un agente su propia
identidad en el gateway: un token emitido por authentik con client credentials, con un scope, y
que expira a los cinco minutos. Terminó nombrando lo que no había cubierto — el servidor de
herramientas MCP de la
parte 4 de orquestación de agentes sigue fiándose de
cualquier cosa que alcance su puerto, issue_refund incluido.
Aquel post fue explícito sobre el límite de lo que había construido:
The MCP server still trusts everyone. Scoping happens in the client. Anything that can reach
127.0.0.1:8770can callissue_refunddirectly, agent or not.
Repartir la caja de herramientas por rol impidió que un agente alcanzara una herramienta que
no le tocaba. No hizo nada contra un curl. Esta parte cierra eso.

