Presented at MCP Dev Summit Toronto 2026 together with Chris Burns
Sched: https://events.linuxfoundation.org/mcp-dev-summit-toronto/program/schedule/?id=1263742
Recording: TBA
Abstract:
The MCP spec recommends servers not to reinvent the access control wheel. Now the question is: what OSS building block will emerge as the access control foundation of choice for the MCP ecosystem, to avoid fragmentation?
The CNCF project Cedar Policy offers a declarative language and engine for attribute-, relation- and role-based access control policies, making it easier to audit, version, reason about and share policies across applications. ToolHive recognized Cedar's utility and uses it to enforce consistent access control across MCP servers.
Cedar is grounded in mathematical logic, which means you can analyze, compare, and query policies themselves, not just evaluate them. Did your refactored policies change any decisions? Is an allow policy actually dead code, always overridden by a stronger deny? Who can access this resource? What can this agent do in the system? Could an AI agent exfiltrate private data to an external sink? These questions Cedar can answer statically and always correctly (unlike LLMs), across all your policies.
After this talk, the audience knows how Cedar could be used to promote ecosystem-wide consistency, and how ToolHive already uses it in production.