The wrong valid token: authenticating an MCP tools server with authentik
- 1Lock down Docker networks
- 2Run containers as non-root
- 3Identity in front of every port
- 4Membership, not just an account
- 5An identity for the agent, not a key
- 6A tool server that checks who is asking
- 7Where the agent can go, not just what it can call
- 8Move the daemon off root
- 9Run the model's own code without trusting it
- 🏆A scope per tool, and a refusal clients can act on
Part 5 gave an agent its own identity at
the gateway: a token issued by authentik over client credentials, carrying a scope, expiring in
five minutes. It ended by naming what it had not covered — the MCP tools server from
agent orchestration part 4 still trusts anything that
can reach its port, issue_refund included.
That post was explicit about the limit of what it had built:
The MCP server still trusts everyone. Scoping happens in the client. Anything that can reach
127.0.0.1:8770can callissue_refunddirectly, agent or not.
Splitting the toolbox per role stopped an agent from reaching a tool it shouldn't. It did
nothing about a curl. This part closes that.

