TwinEthosRequest access

Recommended guardrail

Authenticate every agent tool server and verify every server an agent connects to

Require authentication on every MCP, A2A, or tool-server endpoint, including local development proxies, and have agents reach remote servers only over TLS with credentials. Detect tool servers listening on all interfaces without authentication and agent configurations that reach remote servers over plain HTTP or without credentials. Package and publisher verification is covered by guardrail.agent-component-provenance; an agent's own identity by guardrail.agent-identity-and-action-traceability.

TwinEthos recommendation — not law

This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs.

The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Evidence grade

Standards consensus (2)

2 standards and frameworks · 2 graded incidents.

TwinEthos recommendation, not law. Where binding law applies, the law governs. No binding law in the corpus requires this control yet. 2 standards and frameworks recommend it (IMDA Agentic AI MGF, NIST AML Taxonomy (AI 100-2e2025) — Agentic). 2 graded incidents cited.

Standards and frameworks

Family “An AI agent's authority, reach, inputs, and components are not bounded and accountable”: binding law on related controls is in force in no jurisdiction. Context only: it does not change this guardrail's grade.

Graded incidents

The guard to add

Require a verified token on every MCP or tool-server endpoint, and connect agents to remote servers only over HTTPS with credentials to a fixed, configured URL.

Server side: every MCP, A2A, or tool server validates a bearer token before any tool runs (FastMCP token_verifier= with auth=AuthSettings(...), or an auth middleware in front of the endpoint), and binds to 127.0.0.1 rather than 0.0.0.0 unless authentication is configured; local development proxies follow the same rule. Client side: each remote server entry in .mcp.json or agent config, and each streamablehttp_client / StreamableHTTPClientTransport call, uses an https:// URL fixed in configuration (never taken from model output or retrieved content) and sends credentials via an Authorization header or OAuth.

Example (MCP Python SDK (FastMCP)), before:

mcp = FastMCP('files', host='0.0.0.0')
mcp.run(transport='streamable-http')

After:

from mcp.server.auth.settings import AuthSettings
from pydantic import AnyHttpUrl

# JwtVerifier: our TokenVerifier subclass that checks signature, audience, and expiry
mcp = FastMCP('files', host='0.0.0.0', token_verifier=JwtVerifier(JWKS_URL),
              auth=AuthSettings(issuer_url=AnyHttpUrl('https://auth.example.com'),
                                resource_server_url=AnyHttpUrl('https://files.example.com/mcp'),
                                required_scopes=['files:read']))
mcp.run(transport='streamable-http')

Control: Agent tool servers or agent peers not authenticated. Engineering guidance, not legal advice.

Why

Tool servers are how agents act, so an unauthenticated server can let anyone invoke an agent's tools, and an agent that does not check which server it reached can be steered by an impostor. The maintainers of an MCP developer tool have disclosed a flaw that let unauthenticated requests launch commands, and a security firm found MCP servers reachable from the internet without authentication.

Class: agent security · set: agent containment · maturity: reviewed · confidence: high · id guardrail.agent-tool-server-authentication