Data Sheet

Zero-Bypass MCP Gateway Data Sheet

See how Aurascape lets teams adopt MCP and AI agents at the speed they want while security keeps control of what those agents can reach. This data sheet explains how the Zero-Bypass MCP Gateway pairs an MCP Gateway that governs the tools agents use with an AI Proxy that inspects the agent's conversation with the model, so a tool call that skips the Gateway does not complete.

Executive Overview

Model Context Protocol (MCP) is becoming the standard way AI agents work with enterprise systems. Through MCP, an agent can read tickets in Jira, query records in Salesforce, or push code to GitHub without a person clicking through those apps. That reach is the point, and it is also the exposure. The usual way to secure MCP is a gateway between agents and MCP servers that inspects the connections routed through it.

But an agent only routes through a gateway it is configured to use, and a developer can change that by editing one line. Calls that skip the gateway never arrive to be inspected. Controlling the path agents are supposed to take, while leaving the paths they can take instead ungoverned, secures half the problem. Closing the other half takes a second enforcement point, one the agent cannot route around.

The Aurascape Zero-Bypass MCP Gateway closes this gap. The Gateway governs which tools agents can use and marks every call it approves; the AI Proxy watches the model conversation and checks for that approval record. Because an agent cannot use a tool without it surfacing in the model conversation, a call that skipped the Gateway is caught there and blocked before the model acts. Unsanctioned tool execution does not complete.

The data sheet covers MCP server and tool discovery with automatic enrollment, tool-level sanctioning bound to users and groups, policy actions from coaching to hold-for-approval to blocking, OAuth 2.1 authorization with tokens scoped per user per server, and audit-ready records of every observed MCP conversation. It also walks through two attack scenarios, a tool-poisoning attack and a credential crossing four systems in two tool calls, and maps Aurascape’s coverage to the OWASP MCP Top 10.

Aurascape Solutions