Model Context Protocol (MCP)Algorithmic AI Trading GovernanceSEC 15c3-5 Β· FINRA 3110 Β· RFC 9728

AI Agent β†’ MCP Tool Authorization

An enterprise engineering playbook for financial institutions to govern autonomous AI agents interacting with sensitive execution tools via the Model Context Protocol (MCP): RFC 9728 Protected Resource Metadata, RFC 8707 audience binding, runtime AuthZEN SARC evaluation, real-time circuit breakers (<5ms), zero credential passthrough, and immutable SHA-256 Merkle audit trails (with optional paid Thales Luna Cloud HSM hardware root-of-trust).

Phase 01: Core Architecture & The Gating Model

The Protected MCP Resource Server Model

In algorithmic trading desks and portfolio management workflows, AI agents must not be granted direct, ungated connections to execution tools. Exposing raw order execution tools or database access to autonomous agents without deterministic pre-trade risk controls violates SEC Rule 15c3-5 and FINRA Rule 3110.

AuthHub deploys an RFC 9728 compliant MCP Gateway. Acting as an inline Policy Enforcement Point (PEP), the gateway intercepts every JSON-RPC tools/call, validates client token audience binding, translates arguments into a fine-grained Subject-Action-Resource-Context (SARC) tuple, and invokes live AuthZEN evaluation with active circuit breakers before proxying permitted calls upstream.

MCP Security Gating Matrixsrc/services/mcp-gateway/
Security DimensionUngated Native MCPAuthHub Protected MCP Gateway
AuthenticationStatic token / unauthenticatedOAuth 2.1 RFC 8707 Bound JWT
Tool AuthorizationAll tools exposed to LLMAuthZEN Per-Call SARC Policy Gate
Parameter ChecksNone (Prompt hallucination risk)SpiceDB Quantitative Caveats
Credential FlowAgent holds direct secretsZero Passthrough (Gateway proxies mTLS)
Phase 02: RFC 9728 & RFC 8707 Handshake

Protected Resource Discovery & Audience Binding

When an unauthenticated agent connects to the MCP Gateway, the gateway responds with HTTP 401 Unauthorized containing the WWW-Authenticate header pointing to the RFC 9728 protected resource metadata:

HTTP 401 WWW-Authenticate Challenge
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer realm="AuthHub", resource_metadata="https://api.authhub.cloud/.well-known/oauth-protected-resource"
Content-Type: application/json

{
  "jsonrpc": "2.0",
  "error": {
    "code": -32000,
    "message": "Authentication required. See WWW-Authenticate header for RFC 9728 protected resource metadata."
  }
}
GET /.well-known/oauth-protected-resource
{
  "resource": "https://api.authhub.cloud/mcp",
  "authorization_servers": [
    "https://api.authhub.cloud"
  ],
  "scopes_supported": ["tools:read", "tools:execute", "mcp:read", "mcp:write"],
  "bearer_methods_supported": ["header"],
  "resource_documentation": "https://api.authhub.cloud/docs/mcp-gateway"
}
Phase 03: Protocol Lifecycle & Filtered Discovery

MCP Protocol Handshake & Entitlement-Filtered Tools

Before authenticating, agents can query the stateless server/discover method to inspect supported protocol versions (2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26). Once authenticated with an RFC 8707 audience-bound token, the gateway dynamically prunes the catalog in tools/list so that agents only discover actions they are authorized to execute.

POST /mcp β€” server/discover (Stateless)
{
  "jsonrpc": "2.0",
  "id": 1,
  "result": {
    "supportedProtocolVersions": [
      "2026-07-28",
      "2025-11-25",
      "2025-06-18",
      "2025-03-26"
    ],
    "serverInfo": {
      "name": "AuthHub-MCP-Enterprise-Gateway",
      "version": "1.0.0"
    },
    "authentication": {
      "type": "oauth2",
      "resource_metadata": "https://api.authhub.cloud/.well-known/oauth-protected-resource"
    }
  }
}
POST /mcp β€” initialize (v2026-07-28)
{
  "jsonrpc": "2.0",
  "id": 2,
  "result": {
    "protocolVersion": "2026-07-28",
    "capabilities": {
      "tools": { "listChanged": false },
      "resources": { "subscribe": false }
    },
    "serverInfo": { "name": "AuthHub-MCP-Enterprise-Gateway", "version": "1.0.0" }
  }
}
Phase 04: SARC Translation Engine

Dynamic SARC Translation from tools/call

When an agent executes an MCP tool, AuthHub decomposes the JSON-RPC call into a structured authorization request:

src/services/mcp-gateway/authz-gate.ts
export async function gateToolCall(
  port: number,
  config: McpGatewayConfig,
  principal: ValidatedPrincipal,
  toolName: string,
  args: Record<string, unknown>
): Promise<AuthzDecision> {
  const mapping = mappingFor(config, toolName);
  const resourceId = resolveResourceId(mapping.resourceIdFrom, toolName, args);

  return evaluateSarc(port, principal, {
    subjectType: mapping.subjectType ?? principal.subjectType, // 'agent'
    action: mapping.action,                                   // 'execute'
    resourceType: mapping.resourceType,                       // 'trading_desk'
    resourceId: resourceId,                                   // 'ny-equities'
    label: toolName
  });
}
Phase 05: Caveated ReBAC Schema

Zanzibar Schema with Pre-Trade Limits

AuthHub expresses pre-trade execution bounds in SpiceDB using Quantitative Caveats to prevent orders exceeding authorized risk thresholds:

mcp-schema.zed β€” Quantitative Caveated Model
caveat notional_limit(order_val int, max_limit int) {
  order_val <= max_limit
}

caveat trading_hours(current_time timestamp, market_open timestamp, market_close timestamp) {
  current_time >= market_open && current_time <= market_close
}

definition trading_desk {
  relation supervisor: user
  relation automated_trader: agent with notional_limit and trading_hours
  relation risk_auditor: agent

  permission inspect_positions = risk_auditor + automated_trader + supervisor
  permission execute_swap = automated_trader + supervisor
}

definition agent {}
definition user {}
Phase 06: Live AuthZEN & Circuit Breakers

Sub-5ms Evaluation & Algorithmic Freeze

AuthHub evaluates tool requests against /authzen/v1/evaluation. If live telemetry detects a sudden drawdown or anomalous order frequency, the governance deny-override trips in under 5ms, halting execution immediately.

JSON-RPC Circuit Breaker Deny
{
  "jsonrpc": "2.0",
  "id": 42,
  "error": {
    "code": -32003,
    "message": "Tool execution forbidden by governance circuit breaker",
    "data": {
      "reason": "governance_enforcement_override",
      "metric": "intraday_drawdown_limit_exceeded",
      "threshold": 0.02,
      "current_value": 0.0241
    }
  }
}
Phase 07: Credential Isolation

Zero Token Passthrough & Sanitization

The AI Agent never touches upstream database credentials or FIX engine passwords. The MCP Gateway strips inbound client tokens, validates authorization, and attaches internal gateway mTLS credentials before executing the tool call upstream.

Phase 08: Merkle Audit & Hardware Anchoring

Immutable Tool Execution Audit Trail

HSM: Optional Paid Add-On

Every MCP transaction is sealed into an immutable SHA-256 Merkle hash chain certified with RFC 3161 timestamps:

Standard InclusionIncluded on All Tiers

Software-backed ECDSA P-256 digital signing with RFC 3161 TSA timestamping over per-tenant Merkle roots. Provides mathematical non-repudiation and cryptographic audit verification out-of-the-box.

Thales Luna Cloud HSMPaid Enterprise Add-On

For institutions with strict hardware security mandates, AuthHub offers a dedicated partition on Thales Luna Cloud HSM (DPoD). Keys are non-exportable and FIPS 140-2 Level 3 certified, satisfying FINRA Rule 3110 and SEC Rule 17a-4 audits.

GET /api/v1/audit/records/mcp-tx-99410 β€” Verifiable Attestation
{
  "chain_id": "merkle-mcp-2026-09-18",
  "block_height": 204918,
  "rfc3161_timestamp": "2026-09-18T16:15:02.881Z",
  "hsm_slot": "Luna-Network-HSM-7-Partition-Trading",
  "event": "MCP_TOOL_EXECUTION_PERMITTED",
  "agent_id": "agent:alpha-quant-rebalancer-v2",
  "tool_name": "execute_equity_swap",
  "sarc": {
    "subject": "agent:alpha-quant-rebalancer-v2",
    "action": "execute",
    "resource": "trading_desk:ny-equities",
    "context": { "notional": 2500000, "symbol": "AAPL" }
  },
  "authzen_latency_ms": 3.8,
  "circuit_breaker_status": "nominal",
  "tamper_evident_verified": true
}

Regulatory Compliance Assurance

AuthHub’s MCP Gateway ensures full alignment with SEC Rule 15c3-5 (Pre-Trade Market Access Controls), FINRA Rule 3110 (Supervision of Autonomous Systems), and SEC Rule 17a-4 (Cryptographic Audit Preservation).