Skip to content

docs: clarify MCP gateway API key is leaked by design#26695

Merged
pelikhan merged 3 commits intomainfrom
copilot/update-security-architecture-docs
Apr 16, 2026
Merged

docs: clarify MCP gateway API key is leaked by design#26695
pelikhan merged 3 commits intomainfrom
copilot/update-security-architecture-docs

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Apr 16, 2026

Copilot AI and others added 2 commits April 16, 2026 17:12
Agent-Logs-Url: https://github.com/github/gh-aw/sessions/249a0e4a-598d-40a1-b6e6-8584bce9d02b

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Agent-Logs-Url: https://github.com/github/gh-aw/sessions/249a0e4a-598d-40a1-b6e6-8584bce9d02b

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
@pelikhan
Copy link
Copy Markdown
Collaborator

@lpcox

@pelikhan pelikhan assigned lpcox and unassigned pelikhan and Copilot Apr 16, 2026
@pelikhan pelikhan marked this pull request as ready for review April 16, 2026 18:27
Copilot AI review requested due to automatic review settings April 16, 2026 18:27
@pelikhan pelikhan enabled auto-merge (squash) April 16, 2026 18:27
@pelikhan pelikhan merged commit 7806913 into main Apr 16, 2026
1 check passed
@pelikhan pelikhan deleted the copilot/update-security-architecture-docs branch April 16, 2026 18:28
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates documentation to clarify that the MCP Gateway API key available inside the agent container is not a strong security boundary and should be assumed compromised (“leaked by design”), aligning guidance with the security model discussed in #26584.

Changes:

  • Add a warning to the MCP Gateway authentication reference noting the API key should not be treated as a secure lock against in-container code.
  • Add a corresponding warning in the architecture/security overview describing the same limitation and recommended defense-in-depth controls.
Show a summary per file
File Description
docs/src/content/docs/reference/mcp-gateway.md Adds a warning in the authentication section clarifying the gateway API key is not a strong boundary once code runs in-container.
docs/src/content/docs/introduction/architecture.mdx Adds an architecture warning reinforcing “leaked by design” framing and pointing readers to isolation/network policy/permission staging as primary controls.

Copilot's findings

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 2/2 changed files
  • Comments generated: 0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

4 participants