Verify who is calling.
Every MCP client and agent is detected, fingerprinted, and attributed to an identity, with an assurance tier that tells you how confident that attribution is and per-agent scoping for access control.
Verified before the call is forwarded.
The proxy detects the client type and version on every connection. The Hub's Identities and Clients views roll that up per user and agent with role, assurance, activity, and guardrail and anomaly history, and flag configuration drift across a multi-host fleet.
Client and agent identity
The proxy detects the client type and version on every connection, attributing each call to an identity instead of an anonymous session.
Four-tier assurance model
Every attribution carries a confidence tier, authenticated, gateway-attributed, none, or unattributed, so you know how much to trust who you are looking at.
Member vs non-member
A non-member badge flags activity from accounts that are not in the org, surfacing offboarded employees and service accounts still making calls.
Activity and risk per identity
See tool calls, servers used, guardrail blocks, anomalies, and a peak-hour heatmap for any identity, with deep links into the audit log.
Every identity, with the receipts.
The Identities roster lists every user and agent with role, assurance, and activity, and the Clients view flags configuration drift across a multi-host fleet, managed, partial, or unmanaged, so a bypassed gateway stands out.
Know exactly who is calling your tools.
Join the waitlist to get early access to Ultra's AI-native security and governance.