AuthHub Enterprise Level 3 Journey

Model Context Protocol (MCP) Tool Fleet Governance & OAuth 2.1 PEP

AUTHHUB-JOURNEY-MCP-ENTERPRISE-2026

Governing Model Context Protocol (MCP) Tool Fleets

Deploy an OAuth 2.1 Resource Server Gateway in front of external MCP tools. Enforce method-level AuthZEN authorization, inspect JSON-RPC arguments, bind tools to commercial vendor contracts, and arm sub-50ms Clock-1 kill switches.

Wizard Progress
Step 1 of 5 (20%)
Phase 1 • Shared Foundation

Tenant Registration, Cryptographic Signing & SCIM Ingress

Establish the enterprise cryptographic root of trust (Software default with Thales Luna Cloud HSM option) and configure SCIM 2.0 identity ingress.

โœ“
New Connection: Onboarding Upstream MCP Tool Fleet Fleet #2

Previous configuration saved. Now provisioning a distinct MCP Tool Fleet Gateway.

๐Ÿ›๏ธ

atom-tenant-and-crypto-root

Enterprise root of trust & cryptographic signing

Software WebCrypto
Legal entity identifier used in multi-tenant policy isolation.
Free Tier Default
Root CA for signing MCP tool call tokens, cryptographic Merkle chains, and AuthZEN assertions. Software is standard default (Free); Thales Luna HSM is available as a paid enterprise hardware add-on.
Software Managed Key Root
RFC 7517 WebCrypto RSA-4096 / Ed25519 • Free Tier Included