Search papers, labs, and topics across Lattice.
This paper addresses the governance crisis arising from the rapid adoption of the Model Context Protocol (MCP) in enterprises, where disparate authentication methods led to fragmentation and security risks. It introduces a centralized MCP gateway that unifies authentication and identity delegation across various enterprise tools, implementing a two-axis authentication model and supporting multiple enterprise SSO grants and token-provisioning models. The deployment has successfully streamlined identity management and governance for dozens of MCP servers, enhancing security and operational efficiency.
A centralized MCP gateway can transform fragmented enterprise authentication into a cohesive and secure identity management system.
The Model Context Protocol (MCP) has become the de-facto interface for connecting LLM agents to enterprise tools, and adoption has been explosive: within a year, large organizations went from zero to dozens of internally built MCP servers. That speed created a governance crisis. Each team implemented authentication independently -- some with no auth, some with API keys, some with full OAuth -- producing a fragmented landscape with no consistent way to authorize callers, track who did what, or offboard a departing employee across the fleet. This paper reports an industry deployment that resolves the crisis with a centralized MCP gateway: a single aggregation, governance, and authentication layer that fronts every downstream MCP server. We make four contributions grounded in production experience. First, a two-axis authentication model crossing persona (interactive user vs. automated non-user) with credential type (no-auth, static/dynamic API key, PKCE, client credentials, platform app-context). Second, a gateway authentication layer supporting three enterprise SSO grants and three token-provisioning models: Bring-Your-Own-Token, Generate-Your-Own-Token, and delegated OAuth via RFC 8693 token exchange. Third, three end-to-end identity flows -- User-to-OAuth2, Non-user-to-Service-Account, and User-to-Service-Account -- composing client, gateway, and server. Fourth, the deployment evolution from CDN/WAF/edge perimeter to private MCP tunnels and enterprise-wide connectors. The architecture is in production, fronting dozens of MCP servers across web, desktop, custom-SDK, and low-code clients.