Player not loading? Watch on YouTube
This tutorial explains a multi-tenant MCP gateway built with Descope for identity and credential storage and Bifrost for request enforcement. Acme Corp and Globex Industry use the same gateway with separate credentials. The presenter outlines GitHub, Stack Overflow, and a weather API as possible services, then demonstrates the tenant setup against one backend.
The walkthrough covers server registration, credential connections, a sign-in flow, roles and permissions, and gateway configuration. It uses access key authentication for the demo and discusses dynamic client registration for production. Read and admin scopes appear in JWT claims. A sign-in action takes the tenant ID and API key from user inputs, verifies email through a magic link, and stores the key in the tenant's connection entry.
Bifrost reads the token's tenant claim, checks permissions, and resolves a virtual key to the corresponding credential through Descope connections. The presenter runs requests for each customer, then attempts to access a Globex resource with Acme's JWT. Bifrost blocks that request in the test.
The final section explains onboarding another tenant through the Descope management API and adding its credential mapping to Bifrost. It also describes extending the gateway to additional backend services.