Authorize MCP tool calls without giving agents the credentials
Details
- External ID
- 49695295
- Source
- HN
- Company
- —
- Product
- Authorize MCP tool calls without giving agents the credentials
- Website domain
- github.com
- Launched
- Sept. 14, 2026
- Cohort
- —
- Upvotes
- 7
- Upvotes percentile
- 0.4393939393939394
- Tags
- —
- Fetched at
- Sept. 18, 2026, 5:02 p.m.
- Updated at
- Sept. 18, 2026, 5:02 p.m.
Description
Hey HN, Adam here.We built a small MCP example around a single problem:How do you let an agent use a tool that needs credentials without giving the credentials to the agent?The demo has two tools. One is open. One is protected.When the agent calls the protected tool, Keydris checks the policy first:ALLOW → run the tool REJECT → stopThe credential stays on the server. The agent never sees it.We do the check through a small middleware on the MCP server called the KIT Reader.Repo: https://github.com/keydrisLabs/mcp-auth-keydris-templateWe're early. If you're building with MCP, Claude Code or Codex, I'd love to know how you're handling this today and where you think this approach breaks.We support other elements like integrations etc but would love your feedback
Enrichment
- Theme
- ai coding agents and tooling
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- credential-free authorization layer for mcp tool calls
- Manually corrected
- False
Could you build this?
Yes This is an authorization proxy demo for MCP tools that validates requests against a policy engine before injecting stored credentials and calling downstream APIs.
Discussion
6 comments analyzed.
Competitors mentioned: runjs, 1Claw, Dome Systems
Concerns raised: exposure of long-lived keys if server is compromised
Feature requests: integration with centralized SIEM and log collection, short-lived key issuance
Competitors
Other products that read as similar to this one — 242 launches clear the similarity bar, closest 8 shown.
Attention rank: #124 of 243 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 304 days after the earliest competitor.
- SafeGen · ph · 2026-09-15 · 3 upvotes · similarity 0.57
- Buddy AI Access (MCP) · ph · 2026-09-15 · 99 upvotes · similarity 0.56
- mcp-auth-keydris-template · github · 2026-09-14 · 6 upvotes · similarity 0.50
- Guard Starter · ph · 2026-09-25 · 1 upvotes · similarity 0.49
- cMCP, deny an AI agent's tool call and get a signed receipt · hn · 2026-08-04 · 9 upvotes · similarity 0.49
- Provenant by IdentiQube · ph · 2026-09-12 · 2 upvotes · similarity 0.49
- GuardiAgent · hn · 2025-11-21 · 9 upvotes · similarity 0.49
- SentinelAgent Guard · ph · 2026-09-23 · 2 upvotes · similarity 0.48
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.