GROUNDCONTROL

Ground Control / MCP bridge

MCP bridge policy

This page describes the permissions and tenant boundaries that Ground Control enforces for the MCP bridge. It does not grant access.

01 / OAuth scopes

Two base bridge scopes

Ground Control checks both the token binding and the requested bridge scope. A token with an unknown issuer, resource, audience, or scope is rejected.

mcp:bridge.readBase scope for bridge read access.
mcp:bridge.callBase scope for bridge tool calls.

A served list or resource read is hidden or denied without mcp:bridge.read. A tool call is denied without mcp:bridge.call, before its other action checks.

02 / machine credentials

Bootstrap is tenant-wide

The machine-credential bootstrap route accepts only the following permission values. These permissions are tenant-wide in this bootstrap contract.

mcp:bridge.readmcp:bridge.callworker_facade.claimgoverned_execution.readgoverned_execution.write
  • The request must include a tenant ID.
  • The request tenant ID must match the authenticated browser-session tenant.
  • Each requested scope tenant ID must match both the request and the authenticated tenant.
  • The server evaluates expiry and rate limits with its own clock.
  • The returned secret is shown once. Later reads do not return it.

03 / tenant boundary

The server resolves tenant authority

Ground Control resolves the tenant from the authenticated route. It checks the OAuth token against that route. The client does not choose a different tenant by sending a query value.

A tenant-scope error reports that tenant-scope resolution refused or failed for the request. It covers a cross-tenant denial and a resolver failure. The caller cannot distinguish these cases from this code alone. Check the request tenant and the authorized tenant. Correct a tenant mismatch. If they match, retry or report the error according to the service recovery policy.

Boundary ruleOne authenticated route. One tenant context. No cross-tenant bridge read or write.

04 / claim handoff

A claim handoff is short-lived authority

The local-claim handoff is single-use and purpose-bound. It expires after five minutes. It is not an MCP access token.

The handoff route authenticates only with a single-use bearer handoff secret and mints the server-held claim cookies. The consent route checks only the server-held claim cookie. The completion route checks the claim cookie and a matching CSRF token. The completion request requires an email and a password.

05 / additional authority

A bridge scope is not every permission

Authorization-server discovery lists service-principal action scopes as a vocabulary. The authorization-code flow issues only the two bridge scopes. A headless service principal can need an additional action scope for a governed tool.

Ground Control checks that action scope at call time. Listing a scope does not grant it. The bootstrap allowlist above remains closed to action scopes outside its five tenant-wide values.

Source-backed MCP bridge reference