▾ G11 Media Network: | ChannelCity | ImpresaCity | SecurityOpenLab | Italian Channel Awards | Italian Project Awards | Italian Security Awards | ...
InnovationOpenLab

HTTP Got TLS. APIs Got OAuth. MCP Got Nothing. Permit.io Launches the Gateway to Fix That.

AI agents are already in production. They query CRMs, read codebases, write to data warehouses, and chain tool calls across sensitive systems, all through MCP. But the teams responsible for security a...

Immagine

AI agents are calling enterprise tools in production today with no fine-grained authorization, no delegation tracking, and no audit trail. Permit MCP Gateway adds all three with a single URL change.

TEL AVIV, Israel: AI agents are already in production. They query CRMs, read codebases, write to data warehouses, and chain tool calls across sensitive systems, all through MCP. But the teams responsible for security and compliance face a gap that grows with every new connection: there is no standard way to authorize what an agent can do, track who delegated that authority, or audit what happened after.

This gap is already causing real damage. OWASP classifies Shadow MCP Servers, unsanctioned agent connections that bypass governance, as a top-10 MCP risk. Asana pulled its MCP feature offline for two weeks after a bug leaked customer data across organizations. A critical flaw in the mcp-remote npm package, installed over 558,000 times, gave attackers remote code execution on unpatched machines.

Adoption keeps accelerating. MCP now sees 97 million monthly SDK downloads. Anthropic donated the protocol to the Linux Foundation in December 2025, with OpenAI, Google, Microsoft, AWS, and Block as founding members. Block alone runs over 60 internal MCP servers. The protocol is becoming enterprise infrastructure. The authorization layer has not.

Today, Permit.io is launching Permit MCP Gateway to close that gap. The company has spent years building fine-grained authorization infrastructure, powered by OPA and Google Zanzibar-style relationship-based access control, now used in production at Tesla, Cisco, Intel, BP, and Palo Alto Networks. The gateway applies that same engine to MCP: every agent tool call is authorized in real time, the full delegation chain from human to agent is tracked, and trust ceilings ensure agents never exceed the permissions their human granted.

One URL change. No SDK. No code modifications to servers or agents.

"Every protocol that became enterprise infrastructure eventually needed a purpose-built security layer. MCP has reached that moment," said Or Weis, CEO and co-founder of Permit.io. "The difference is that agents do not just read, they act. Without authorization, the blast radius is not a data leak. It is an autonomous system doing things no one approved."

Permit MCP Gateway is deployed by enterprise customers and available in both hosted SaaS and on-premises configurations.

Related links

Product: permit.io/mcp-gateway
Try it: app.agent.security
Docs: docs.permit.io/permit-mcp-gateway/overview
YouTube:

Fonte: Business Wire

If you liked this article and want to stay up to date with news from InnovationOpenLab.com subscribe to ours Free newsletter.

Related news

Last News

RSA at Cybertech Europe 2024

Alaa Abdul Nabi, Vice President, Sales International at RSA presents the innovations the vendor brings to Cybertech as part of a passwordless vision for…

Italian Security Awards 2024: G11 Media honours the best of Italian cybersecurity

G11 Media's SecurityOpenLab magazine rewards excellence in cybersecurity: the best vendors based on user votes

How Austria is making its AI ecosystem grow

Always keeping an European perspective, Austria has developed a thriving AI ecosystem that now can attract talents and companies from other countries

Sparkle and Telsy test Quantum Key Distribution in practice

Successfully completing a Proof of Concept implementation in Athens, the two Italian companies prove that QKD can be easily implemented also in pre-existing…

Most read

Alibaba Group Announces December Quarter 2025 Results

$BABA #alibaba--Alibaba Group Holding Limited (NYSE: BABA and HKEX: 9988 (HKD Counter) and 89988 (RMB Counter), “Alibaba” or “Alibaba Group”) today announced…

Cobalt Introduces New AI Capabilities for Continuous Pentesting

RSA Conference -- Cobalt, the pioneer of penetration testing as a service (PTaaS) and a leading provider of human-led, AI-powered offensive security solutions,…

EQTY Lab Announces Verifiable Runtime to Secure AI Agents Across the NVIDIA…

GTC 2026 – EQTY LAB announced today at NVIDIA GTC 2026 the launch of its new Verifiable Runtime, a solution engineered to secure and optimize autonomous…

FiscalNote Reports Fourth Quarter and Full Year 2025 Financial Results

FiscalNote Holdings, Inc. (NYSE: NOTE) (“FiscalNote” or the “Company”), a global leader in AI-driven policy and regulatory intelligence, today reported…

Newsletter signup

Join our mailing list to get weekly updates delivered to your inbox.

Sign me up!