# MCP Identity Gateway content inspection coverage

A security update for the MCP Identity Gateway broadens the MCP traffic that [Content Security](/user-guide/access-policies/content-security/) inspects.

The Gateway normalizes responses that MCP servers stream as server-sent events before inspection, so Content Security inspects those responses along with the rest of the session. The Gateway also applies the policy’s **Fail Open on Error** setting to requests it can’t read and to protocol errors. A policy set to fail closed blocks those requests.

These updates shipped in the same build as the [MCP Identity Gateway 1.33.5654 release](/changelog/entry/2026-08-07-mcp-identity-gateway-1-33-5654-release).