MCP SECURITY GATEWAY
aegis
aegis is a gateway between your AI agents and your MCP servers. It authenticates, authorizes and scans each tool call, and records each decision in a tamper-evident audit log, without changes to your servers.
- HTTP endpoints
- 44
- Injection rules
- 43
- PII & secret detectors
- 13
- Gateway error codes
- 12
Why aegis#
Authenticate every call
JWTs are verified as HS256 or RS256 via JWKS. The tenant comes from a claim, and an allow-list can restrict which tenants are served.
Per-tool RBAC
Policies apply per role, server and tool glob, with allow, deny or approve effects. Deny wins over approve and allow, a call that matches no rule is denied, and tools/list hides the tools a caller cannot reach.
Injection & egress scanning
Shell and prompt-injection rules run on every string in a call's params, keys included. By default, a call that would send a credential, card number or SSN to the upstream is refused.
PII & secret redaction
Responses are scanned for private keys, API tokens, JWTs, card numbers and SSNs. Hits are redacted by default, and you can choose to block the response or only log them.
Tool integrity
Each tool's name, description and input schema are pinned by SHA-256 the first time aegis sees them. If the definition later changes, the tool is quarantined until an operator reviews and re-pins it.
Approvals & kill-switch
An approve policy holds a call until an operator decides, and an approval admits that exact call once. A kill-switch stops traffic for a tenant, a server or a tool, and every replica picks it up within one refresh interval, 2 seconds by default.
Tamper-evident audit
Each allow, deny, block and error is appended to an HMAC-SHA256 hash chain in ClickHouse, keyed by a secret the database never sees. A verify endpoint recomputes the chain.
Resilience & operations
Per-upstream circuit breakers, backpressure, bounded retries, mTLS to backends, Prometheus metrics and a hardened Helm chart.
What it covers#
aegis secures MCP tool traffic: initialize, ping, tools/list and tools/call, plus notifications, which it acknowledges with HTTP 202. It does not proxy MCP resources or prompts. initialize advertises the tools capability only, and any other method returns -32601. Within that surface, aegis handles identity (JWT verification and tenant scoping), rate limiting (per session and per tool), authorization (per-tool RBAC and approval holds), threat filtering (argument validation, injection and egress scanning, response PII and secret scanning, tool pinning), operator controls (the kill-switch, quarantine and an admin API), resilience (circuit breakers, backpressure and bounded retries) and audit. Once a caller is authenticated, refusals come back as JSON-RPC errors with distinct codes, so a client can tell a policy denial apart from a threat block or an unavailable upstream.
How it fits#
aegis is a reverse proxy written in Rust on Tokio and Axum, and it listens on port 8080. You point your MCP client at the gateway's /mcp or /v1/invoke endpoint instead of at the upstream server, and aegis forwards each call it allows to the server that owns the tool. Redis is required and holds sessions, rate limits and kill-switches. Postgres holds the server catalog, RBAC policies and approvals, and ClickHouse holds the audit chain. The gateway is configured through environment variables, and each optional subsystem stays off until its variables are set. This applies to identity, policy and audit too: with no JWT verifier configured every caller runs as anonymous, without DATABASE_URL RBAC is disabled, and without CLICKHOUSE_URL nothing is audited. Before you expose the gateway to real traffic, configure a JWT verifier, DATABASE_URL, CLICKHOUSE_URL and a strong AUDIT_HMAC_KEY. For a product-level view, see the aegis product page.
Next steps#
- Quick start: run the full stack locally and send your first tool call through the gateway.
- How aegis works: follow a
tools/callthrough each check, in order. - Security model: what aegis enforces, where it fails closed and what it does not cover.
- Configuration: the environment variables that turn each subsystem on and tune it.
- Error codes: every refusal code and the HTTP status that goes with it.