Skip to content

A security update for the MCP Identity Gateway broadens the MCP traffic that Content Security inspects.

The Gateway normalizes responses that MCP servers stream as server-sent events before inspection, so Content Security inspects those responses along with the rest of the session. The Gateway also applies the policy’s Fail Open on Error setting to requests it can’t read and to protocol errors. A policy set to fail closed blocks those requests.

These updates shipped in the same build as the MCP Identity Gateway 1.33.5654 release.

← Back to changelog