Nordic APIs Summit 2026 - Agenda is live Register now!
Supported by Curity Logotype

Session

MCP Is Not a Security Boundary

Yossi Eliaz Incredibuild

Problem: Teams wiring AI agents into MCP servers often assume the protocol enforces access boundaries, but it doesn’t. MCP defines how agents discover and call tools, not what those tools are allowed to touch, so a single prompt injection or tool-chaining bug can turn into a credential exfiltration path.

Solution: This talk breaks down where MCP’s trust model actually ends, walks through real failure modes when agents get more access than intended, and shows practical patterns for sandboxing, credential scoping, and egress brokering that keep the API surface honest.

Audience takeaways: Attendees leave with a checklist for auditing their own MCP-connected agent deployments and concrete architecture patterns — credential-free sandboxes, scoped tokens, anomaly monitoring — they can apply to any agent-to-API integration this week.

This session will be held at at our upcoming event:

Nordic APIs Summit 2026

Register Learn More
Smarter Tech Decisions Using APIs

Smarter Tech Decisions Using APIs

API blog

High impact blog posts and eBooks on API business models, and tech advice

API conferences

Connect with market leading platform creators at our events

API community

Join a helpful community of API practitioners

API Insights Straight to Your Inbox!

Can't make it to the event? Signup to the Nordic APIs newsletter for quality content. High impact blog posts on API business models and tech advice.

By clicking below, you agree that we process your information per the terms in our Privacy Policy.

Join Our Thriving Community

Become a part of our global community of API practitioners and enthusiasts. Share your insights on the blog, speak at an event or exhibit at our conferences and create new business relationships with decision makers and top influencers responsible for API solutions.