Docs

Connection Security

Protect MCP connection credentials and authenticate communication with external services.

Connection Security has no page of its own — it is the pair of mechanisms that MCP Server Connection and Discovery both depend on to keep credentials safe and to know whether a server is actually up. There are two distinct backends underneath it.

Credential encryption wraps every credential value the connect wizard collects before it is written to a Kubernetes Secret: AES-256-GCM with a single DP-level key from FABURAI_DP_SECRETS_KEY, one value at a time (not the whole Secret as one blob), so the Secret's per-key shape stays what the vendor's pod expects. Each ciphertext carries a 4-byte fbe1 marker so the read path can tell an already-encrypted value from legacy plaintext without decrypting it first, which makes re-encryption idempotent — writing the same value twice never double-wraps it. If no key is configured the DP falls back to writing values verbatim (a dev-mode path, not a production default); a legacy plaintext value encountered on read is passed through with a warning log rather than failed, so a partially-migrated Secret keeps working while it's flagged for re-encryption. When a Secret already exists, an update decrypts every existing key, merges in the new ones, and re-encrypts the whole set — so a Secret that mixes operator-set plaintext and wizard-set ciphertext collapses to all-ciphertext on the next write rather than staying mixed indefinitely.

Endpoint reachability is a continuous background probe, distinct from the one-time TCP dial MCP Server Connection runs while a user is filling out the connect form. Every 60 seconds it sends an MCP initialize request to every registered server with an endpoint (skipping synthetic demo-fixture rows), attaching a bearer token from the server's spec if one is set, and records the result — healthy on a 2xx response, unhealthy otherwise, with the latency and any error message — back onto the server's status and into its activity feed. This is what feeds the health dot shown on MCP Server Mesh.

Authentication for outbound calls to external, OAuth-authenticated MCP endpoints is handled by a shared token cache: for the one vendor currently wired (AWS), it mints a Bearer via the AWS Sign-In service's CreateOAuth2TokenWithIAM call from IAM keys pulled out of the synced Secret, and caches the result until it's close to expiry. A server can declare auth_type as api_key, oauth, oidc, or mtls, but only api_key and oauth are actually exercised by the outbound proxy path today — a server configured with oidc or mtls is accepted at registration but the proxy that forwards external calls rejects it at call time.

Reference

Features

Credential encryption
description
AES-256-GCM encryption of each stored credential value with a single DP-level key, marked so already-encrypted values are never double-wrapped. Falls back to storing values verbatim only when no key is configured.
Kubernetes Secret integration
description
Reading and writing the Kubernetes Secret a vendor's MCP pod mounts credentials from — created if absent, merged and re-encrypted as a whole if it already exists, so hand-set operator keys survive a wizard update.
OAuth token handling
description
Minting and caching short-lived Bearer tokens for OAuth-authenticated external MCP endpoints — today, AWS's managed MCP via IAM-key-based Sign-In token exchange — so the raw IAM credential is never sent to the upstream server directly.
Vendor credential configuration
description
Per-vendor mapping from the connect wizard's uppercase env-style credential keys to the exact key names and casing a vendor's pod manifest expects, so the same wizard produces a Secret each vendor's pod can actually read.
Connection authentication
description
The auth_type recorded on a server — api_key, oauth, oidc, or mtls. Only api_key and oauth are handled by the outbound call path today; oidc and mtls can be selected at registration but are rejected when a call is actually proxied.
Endpoint reachability
description
A recurring health probe that sends an MCP initialize request to every registered server every 60 seconds and records healthy/unhealthy, latency, and any error, distinct from the one-time TCP dial run during connection setup.