Delegation
Bounded authority—not a copied user role
A person or governed process grants an agent bounded capability. The agent does not inherit an unrestricted copy of the delegator’s access.
EmpowerID Identity Fabric Service
EmpowerID MCP Gateway is the MCP-aware Policy Enforcement Point of Identity Fabric. It verifies who an agent represents, scopes tool discovery, authorizes each invocation through Governed Authorization, enforces constraints, protects downstream credentials, and records correlated action evidence.
MCP carries the call. EmpowerID determines whether the call may become an enterprise action.
OpenID AuthZEN connects the MCP PEP to the EmpowerID PDP on governed paths.
Read the MCP Gateway whitepaper →Governed tool invocation
Tool call received
MCP invocation enters the governed path
Gate checks
PDP decision
Permit + constraints & obligations
Dispatch
Routed with enforced constraints · obligations applied
Credential · Injected at the boundary · never returned to the agent
Receipt
Signed receipt · full causal chain on configured paths
The Model Context Protocol gives AI applications a standard way to discover and invoke tools—and its authorization specifications establish an important OAuth foundation. But access to an MCP server is not the same as authority to perform every action that server exposes. EmpowerID MCP Gateway makes identity, delegation, policy, tool integrity, credentials, and evidence part of the invocation path—not agent prompts, application shortcuts, or post-event log reconstruction.
Delegate deliberately. Discover selectively. Authorize every invocation. Preserve the evidence.
Delegation
A person or governed process grants an agent bounded capability. The agent does not inherit an unrestricted copy of the delegator’s access.
Discovery
Before an agent plans, EmpowerID exposes an appropriately scoped catalog from delegation and Identity Fabric context—including virtual MCP servers for different roles and use cases.
Invocation
Each tool call re-verifies binding, delegation, schema integrity, and PDP authorization. Policy change, revocation, or schema drift can stop the next governed invocation.
Delegation, discovery, and invocation as three governed moments on the tool path.
Traditional API gateways understand hosts, paths, methods, and tokens. MCP requests carry additional meaning: a model-selected tool, a declared schema, structured parameters, agent identity, and often delegated human authority. EmpowerID evaluates that semantic context before dispatch.
| Enforcement input | What EmpowerID evaluates |
|---|---|
| Subject | Agent identity, represented user or service, trust and lifecycle context |
| Action | Stable authorization operation for discovery or invocation |
| Resource | Tool, target system, organization, data scope, and object context |
| Context | Delegation, schema pin, plan step, session, risk, parameters, and environment |
Validate tokens, resolve agent identity, and establish represented human or service context. Sender-constrained tokens where configured.
Boundary note
Binding resolves agent, client, and represented identity before tool semantics are evaluated.
Seven-step governed invocation sequence with policy decision at step four.
Receipts prove what the EmpowerID-controlled boundary authorized, dispatched, denied, cancelled, or observed—not unqualified downstream business effect.
Cryptographically bind approved tool schemas to the invocation path and fail closed when presented definitions no longer match. Controlled grace windows can support planned upgrades.
For selected high-risk journeys, optional plan contracts can bind invocation to an approved tool, step, and parameter fingerprint.
Restrict accepted parameters, inject authoritative scope, constrain destinations, and re-check redirects to prevent legitimate calls from becoming unintended data paths.
Enterprise actions may require approval, OAuth consent, missing information, or long-running fulfillment. The EmpowerID MCP Bridge maps supported orchestration states into MCP Tasks and Elicitation for compatible clients.
MCP Tasks remain experimental in the November 2025 specification. EmpowerID negotiates client capabilities and uses progressive compatibility rather than assuming uniform client support.
Vault-backed outbound authentication for registered servers and connectors. The agent receives authority to request the action—not possession of downstream secrets injected at the protected boundary.
The agent receives authority to request the action—not possession of downstream secrets injected at the protected boundary.
Three-zone custody model: agent context, gateway boundary, downstream systems.
| Fabric service | Role on the path |
|---|---|
| Identity Provider and credentials | Authenticate principals, issue tokens, support identity chaining and credential journeys |
| Governed Authorization | PDP evaluation through AuthZEN-compatible interfaces |
| Identity graph and membership | Agent, user, delegation, tool, and organization relationships |
| Orchestration & Fulfillment | Enterprise connector execution and durable workflows |
| MCP Gateway | MCP PEP at discovery and invocation; credential protection and routing |
| LLM Gateway | Model PEP—classification, budget, provider credentials, and allow-path receipts |
| Agent Governance & Execution | Broader agent controls beyond tool boundary—including governed execution where required |
Bounded administrative actions tied to a delegating engineer, current policy, and a governed tool definition.
Access-request and lifecycle operations without unrestricted admin credentials or unfiltered identity tool catalogs.
Protected per-user OAuth credentials for supported SaaS platforms while keeping tokens outside agent-visible context.
Register internal and third-party MCP services and publish different governed catalog views per agent population.
Stronger delegation, schema, plan, parameter, and evidence controls for money, access, regulated data, or infrastructure changes.
| Standard or protocol | How it is used |
|---|---|
| Model Context Protocol | Tool discovery and invocation; capability negotiation; Elicitation and supported Task patterns |
| OpenID Authorization API / AuthZEN | PEP-to-PDP communication for governed MCP decisions |
| OAuth 2.0 (RFC 9728, 8693, 9449) | Protected resource metadata, token exchange, and optional sender-constrained tokens where configured |
| JSON Web Signature (RFC 7515) | Signed schema, plan, and receipt artifacts on configured paths |
| OpenID Shared Signals (SSF) / CAEP | Continuous access and risk signals where deployed—interpreted by policy, not treated as commands |
| Identity Assurance (ID-JAG) / Cross-App Access patterns | Agent and delegated identity context at the gateway alongside per-tool authorization |
Credible agent security requires defense in depth. MCP Gateway focuses on identity, authorization, tool integrity, credential, and evidence controls at the tool boundary.
Broader agent runtime controls live in Agent Governance & Execution.
Feature availability—including schema pinning, plan contracts, Task/Elicitation support, outbound credential modes, receipt coverage, and client transports—varies by edition, deployment, and release. Confirm scope with EmpowerID before customer-specific commitments. Packaging as a standalone Fabric service versus inclusion with Agent Governance requires commercial confirmation.
See how EmpowerID MCP Gateway connects agent identity, delegated authority, fine-grained policy, protected credentials, and correlated evidence at the tool boundary.
Online
Powered by EmpowerID AI