Add RBAC support to Server tooling/resources/prompts #1014
gabe4coding
started this conversation in
Ideas
Replies: 1 comment 2 replies
-
|
The Eunomia Authorization Middleware you are pointing out addresses exactly that need: fine-grained authorization for tools. With that you can easily implement RBAC to control tool access within your org. Currently, the middleware does not affect the visibility of tools, but their use only, which is the important part from a security perspective - but we'd be happy to further discuss with you potential enhancements to address this if you still think it's relevant. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Not sure if this should maybe be proposed on MCP Specification, however on Enterprise, it's likely happening that MCP are built by capability.
But not all the tools can be available to Agents.
This means that we should be able to define, depending on the client, which tools should be enabled.
An RBAC based on the Bearer token scopes, could help to customize the MCP tooling, depending on the permission given.
I saw that there is an Eunomia middleware, that help to prevent access do denied resources, however (correct if i'm wrong) that doesn't impact the visibility of the tools.
Beta Was this translation helpful? Give feedback.
All reactions