Menu
Secure consequential tool calls before execution.
The safest place to control an AI agent action is inside the trusted runtime immediately before the external side effect.
1. Keep security credentials in the trusted runtime
Do not expose agent-security credentials in browser or untrusted client code. The server, agent runtime or trusted MCP server should hold the credential.
2. Map the tool call to a resource and action
Translate the proposed tool execution into an explicit authorization request, such as a payment resource and submit action.
3. Ask for authorization before calling the tool
Send the protected request to the authorization boundary. Continue only when the resulting decision permits execution. Sensitive actions can pause for human approval.
4. Record the execution outcome
After the external action finishes, record whether execution occurred and its outcome. This links the authorization decision to what actually happened.
5. Preserve evidence for incident response
Attributable runtime evidence makes it possible to investigate agent behavior, identify affected authority and support containment and recovery.
Secure MCP tool calls with Nodra