TwinEthosRequest access

Control

Agent tool servers or agent peers not authenticated

Every MCP, A2A, or tool-server endpoint authenticates its callers, including local development proxies, and every agent connects to remote servers over TLS to a configured, expected server identity.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: An AI agent's authority, reach, inputs, and components are not bounded and accountable · control id cond.agent-tool-server-not-authenticated

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

The guard to add

Require a verified token on every MCP or tool-server endpoint, and connect agents to remote servers only over HTTPS with credentials to a fixed, configured URL.

Server side: every MCP, A2A, or tool server validates a bearer token before any tool runs (FastMCP token_verifier= with auth=AuthSettings(...), or an auth middleware in front of the endpoint), and binds to 127.0.0.1 rather than 0.0.0.0 unless authentication is configured; local development proxies follow the same rule. Client side: each remote server entry in .mcp.json or agent config, and each streamablehttp_client / StreamableHTTPClientTransport call, uses an https:// URL fixed in configuration (never taken from model output or retrieved content) and sends credentials via an Authorization header or OAuth.

Where it goes: 1 application source code, 3 config and feature flags, 6 API calls and integrations, 15 agent action surface.

What reviewers look for: no FastMCP(...) or mcp.run(...) bound to 0.0.0.0 without auth= or token_verifier=; MCP client configs and client code using https:// for non-localhost servers with headers.Authorization, oauth, or auth settings present; server URLs coming from config, not from the conversation.

Example (MCP Python SDK (FastMCP)), before:

mcp = FastMCP('files', host='0.0.0.0')
mcp.run(transport='streamable-http')

After:

from mcp.server.auth.settings import AuthSettings
from pydantic import AnyHttpUrl

# JwtVerifier: our TokenVerifier subclass that checks signature, audience, and expiry
mcp = FastMCP('files', host='0.0.0.0', token_verifier=JwtVerifier(JWKS_URL),
              auth=AuthSettings(issuer_url=AnyHttpUrl('https://auth.example.com'),
                                resource_server_url=AnyHttpUrl('https://files.example.com/mcp'),
                                required_scopes=['files:read']))
mcp.run(transport='streamable-http')

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

TwinEthos recommendation (not law) (1)

Related incidents