Datawiza

AI agent governance

Connect MCP to Entra ID, Okta, or Your Enterprise IdP

Datawiza Agent Gateway verifies enterprise IdP tokens and uses validated claims to make MCP access decisions before agents reach sensitive tools.

Datawiza Agent Gateway validating MCP access tokens

For MCP teams

MCP needs enterprise identity before tool access

MCP makes tools easy for agents to discover and call. That becomes risky when servers expose SaaS data, internal APIs, databases, tickets, code repositories, or business workflows.

The core question: which user, which agent, which tool, which action, under which policy?

Validated IdP claims

MCP access should carry validated IdP claims before a tool call is allowed, whether the token represents an agent, workload, user, or delegated session.

Tool permissions

One MCP server may expose read, write, export, and admin-style tools. Access needs to be checked at the tool and action level.

Audit trail

Security teams need proof of who called which tool, what policy applied, and what happened next.

Partners & integrations

Validate MCP access with your enterprise IdP

Review supported identity integrations, cloud marketplace paths, and procurement channels for Datawiza Agent Gateway.

View partners & integrations

Gateway pattern

Put enterprise token validation in front of MCP tools

Datawiza Agent Gateway sits between agents and MCP servers. Agents authenticate with your enterprise IdP, send their access token to the gateway, and Datawiza validates the token before applying tool-level policy.

Enterprise IdP integration

Let agents authenticate with Microsoft Entra ID, Okta, Ping, AWS IAM, or another IdP, then present signed access tokens to Datawiza for validation.

Claims-based tool policy

Map validated groups, scopes, app roles, and custom claims to allowed MCP servers, tools, and actions.

Token validation and audit

Validate issuer, audience, signature, expiry, scopes, and claims, then capture user, agent, tool, policy, and outcome for audit.

Architecture

A Gateway Between Agents and MCP Servers

Agent traffic flows through Datawiza before it reaches MCP servers. Validated IdP claims and policy become part of every tool-call decision.

Step 1

Agent or MCP client

Authenticates with Entra ID, Okta, or another IdP and receives a signed access token.

Step 2

Datawiza Agent Gateway

Validates issuer, audience, signature, expiry, scopes, and claims, then checks MCP server, tool, and action policy.

Step 3

MCP servers and tools

Receive only approved MCP requests. Denied, approved, and approval-routed decisions are logged.

Identity providers

Entra IDOktaPingAWS IAMOAuth / OIDC

Deployment options

Azure / AWS / Google CloudOn-premises / private networkDatawiza-hosted service

Token validation: trust the IdP token only after Datawiza verifies it.

Tool policy: allow or deny by agent, claim, MCP server, tool, action, and environment.

Audit: record who or what called the tool, which policy matched, and the outcome.

Workflow

How MCP token validation works with your IdP

Start with one MCP server and one agent workflow. Prove the token validation, policy, and audit path before expanding to more tools.

  1. 1Route MCP traffic through DatawizaPoint the MCP client or agent workflow at the Datawiza gateway endpoint instead of a direct MCP server URL.
  2. 2Validate the token and enforce policyValidate the enterprise IdP access token, then evaluate the user, agent, server, tool, and action.
  3. 3Forward requests and record the decisionForward approved MCP requests and log denied, approved, or approval-routed decisions.

Comparison

Direct MCP access vs. Datawiza Agent Gateway

Area
Direct MCP connectivity
With Datawiza Agent Gateway
Access path
Agents connect directly to MCP servers
Agents present enterprise IdP tokens to one gateway
Identity context
Authorization varies by MCP server
Validated IdP claims are available before server, tool, or action policy runs
Token handling
Tokens and API keys can spread into local configs
Gateway validates enterprise IdP tokens before MCP tools run
Audit
Logs are split across clients, servers, and tools
Every tool call records identity, policy, decision, and outcome

IdP policy examples

Use IdP claims in MCP decisions

Group claims

Use Entra ID, Okta, or enterprise IdP group claims to distinguish finance users, managers, contractors, and service agents.

Scope and claim checks

Use scopes, app roles, audiences, and custom claims as trusted identity context before MCP tools are allowed.

Identity-rich audit

Send MCP access logs to your SIEM with issuer, subject, group, agent, server, tool, decision, and result.

Next step

Want to validate MCP access with your enterprise IdP?

Bring one MCP server, one agent workflow, and your IdP token requirements. We can map where token validation, policy, and audit should sit before you roll out MCP broadly.

Related tutorial

Add Entra ID authentication to Claude MCP servers

Follow the step-by-step guide for protecting an MCP server with Datawiza Agent Gateway and Microsoft Entra ID before Claude or another MCP client reaches sensitive tools.

Read the tutorial