The Agent Identity Problem: Why OAuth Isn't Enough for MCP

When an AI agent calls a tool, three principals are involved but only one has an identity. OAuth authenticates the user — but not the agent’s intent. Here’s what enterprise auth architecture for MCP actually needs, and how to build toward it without waiting for the ecosystem to figure it out.

July 31, 2026 · 8 min · Matt Konda

The MCP Attack Surface: What Security Teams Are Missing

MCP flips a traditional security assumption — the callee can influence the caller. That’s what makes it powerful, and it’s what your security team needs to understand. A practical catalog of the attack surfaces that matter, with mitigations that don’t slow teams down.

July 24, 2026 · 9 min · Matt Konda

Threat Modeling MCP: 6 Trust Boundaries Your Security Team Should Map

MCP is the right bet for connecting AI agents to enterprise tools. But deploying it well means understanding the trust boundaries. I applied STRIDE to the protocol end-to-end — here’s what to focus on so your team can move fast without getting burned.

July 17, 2026 · 9 min · Matt Konda

AI Security: Separating What's Real from What's Marketing

Everyone is selling AI security. Most of it is repackaged application security with a new label. Here’s what actually matters when securing AI systems — and using AI to secure yours.

July 3, 2026 · 4 min · Matt Konda