MCPIdentity: Keyless MCP Agent Authentication Patterns on Kubernetes With Keycloak… M. Dayıoğlu
Keycloak Kubernetes Spire Mcp Authentication Security Zero Trust Jwt Dpop Opa Cloud Native Spiffe Agent Authentication Identity Management
MCPIdentity demonstrates how to eliminate static credentials for MCP (Model Context Protocol) agents on Kubernetes by using SPIRE for runtime identity attestation (issuing short-lived JWT-SVIDs) and Keycloak for agent registration via CIMD documents. The solution uses DPoP to bind tokens to in-memory keypairs and OPA to enforce trust policies per tool call. Target audience is platform engineers and security architects implementing zero-trust authentication for AI agents in Kubernetes environments.