---
格式版本: 2
标题: "A Gateway Architecture for Enterprise MCP Authentication: Unifying Heterogeneous Auth, Identity Delegation, and the User"
原文链接: "https://arxiv.org/abs/2608.10760"
发布日期: "2026-08-11"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Tue, 11 Aug 2026 10:19:20 UTC (19 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-12T11:15:57+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-12T11:13:54+08:00"
入库时间: "2026-08-12T03:15:57.162Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=deployment&searchtype=all"
匹配关键词:
  - "deployment"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "主题为MCP认证网关架构，与超节点/AI Rack/机柜级AI基础设施无任何关联，属于明显无关内容。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-12T11:16:04+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 2
AI技术细节: 1
AI商业部署信号: 0
AI完整性: 0
采集批次: "2026年8月12日2点04分20秒"
采集批次ID: "20260812-020420-289"
去重键: "https://arxiv.org/abs/2608.10760"
---

## Computer Science > Cryptography and Security

## Title:A Gateway Architecture for Enterprise MCP Authentication: Unifying Heterogeneous Auth, Identity Delegation, and the User / Non-User Persona Problem

Authors:[Suraj Kumar](https://arxiv.org/search/cs?searchtype=author&query=Kumar,+S), [Amy Wang](https://arxiv.org/search/cs?searchtype=author&query=Wang,+A), [Srinivasan Manoharan](https://arxiv.org/search/cs?searchtype=author&query=Manoharan,+S)

[View PDF](https://arxiv.org/pdf/2608.10760) [HTML (experimental)](https://arxiv.org/html/2608.10760v1)

> Abstract:The Model Context Protocol (MCP) has become the de-facto interface for connecting LLM agents to enterprise tools, and adoption has been explosive: within a year, large organizations went from zero to dozens of internally built MCP servers. That speed created a governance crisis. Each team implemented authentication independently -- some with no auth, some with API keys, some with full OAuth -- producing a fragmented landscape with no consistent way to authorize callers, track who did what, or offboard a departing employee across the fleet. This paper reports an industry deployment that resolves the crisis with a centralized MCP gateway: a single aggregation, governance, and authentication layer that fronts every downstream MCP server.  
> We make four contributions grounded in production experience. First, a two-axis authentication model crossing persona (interactive user vs. automated non-user) with credential type (no-auth, static/dynamic API key, PKCE, client credentials, platform app-context). Second, a gateway authentication layer supporting three enterprise SSO grants and three token-provisioning models: Bring-Your-Own-Token, Generate-Your-Own-Token, and delegated OAuth via RFC 8693 token exchange. Third, three end-to-end identity flows -- User-to-OAuth2, Non-user-to-Service-Account, and User-to-Service-Account -- composing client, gateway, and server. Fourth, the deployment evolution from CDN/WAF/edge perimeter to private MCP tunnels and enterprise-wide connectors. The architecture is in production, fronting dozens of MCP servers across web, desktop, custom-SDK, and low-code clients.

| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) |
| --- | --- |
| Cite as: | [arXiv:2608.10760](https://arxiv.org/abs/2608.10760) \[cs.CR\] |
|  | (or [arXiv:2608.10760v1](https://arxiv.org/abs/2608.10760v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.10760](https://doi.org/10.48550/arXiv.2608.10760) |

## Submission history

From: Suraj Kumar \[[view email](https://arxiv.org/show-email/042ce136/2608.10760)\]  
**\[v1\]** Tue, 11 Aug 2026 10:19:20 UTC (19 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.10760) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
