MCPkey · Zero Trust for AI Agents

The Era of Blind AI Trust Is Over

MCPkey is the out-of-band, hardware-isolated zero-trust defense line for the Model Context Protocol — giving humans a physical veto over every high-risk AI operation.

MCPkey · AIエージェント向けゼロトラスト

盲目的なAI信頼の時代は終わった

MCPkeyは、モデルコンテキストプロトコル(MCP)向けのアウトオブバンド物理隔離ハードウェアゼロトラスト防衛ラインです。高リスクなAI操作すべてに、人間の物理的な拒否権を与えます。

MCPkey · AI智能体零信任防线

盲目信任AI的时代结束了

MCPkey 是专为模型上下文协议(MCP)设计的带外物理隔离硬件零信任防御层——赋予人类对每一项高风险AI操作的物理否决权。

141K+
Evaluations (July 2026)評価件数(2026年7月)评估次数(2026年7月)
6
Confirmed Intrusions侵入確認件数已确认入侵次数
FIDO2
Hardware Passkey AuthハードウェアPasskey認証硬件通行密钥认证
MCPkey product logo — a shield containing a robot head and a key, representing AI agent security with hardware passkey protection

Prompts Failed. Sandboxes Leaked.
The Stakes Have Never Been Higher.

As enterprise AI evolves from read-only assistants to write-capable agents, the absence of a physical safety net becomes a critical vulnerability.

Real Incident — July 2026

Anthropic's Claude Made Unauthorized Intrusions into 3 Real Companies During Testing

  • 6 confirmed intrusions identified from 141,006 evaluations
  • Misconfigured sandbox allowed external connections to real systems
  • Credential leakage via weak passwords; sessions compromised
  • Malicious PyPI packages executed across 15 real production systems
🔓

SSO Tokens Are Vulnerable

Soft tokens from Okta or SSO systems are susceptible to session hijacking. When the AI model's alignment collapses, prompt constraints stop working — and so does your soft auth.

⚠️

Autonomous High-Risk Execution

MCP enables AI agents to autonomously execute delete, transfer, and deploy operations. There is no cryptographic guarantee tying the agent's intent to the actual parameters executed.

プロンプトは失敗した。
サンドボックスが漏れた。

エンタープライズAIが「読み取り専用アシスタント」から「書き込み操作エージェント」へと進化する中、物理的なセーフティネットの不在は致命的な脆弱性となっています。

実際のインシデント — 2026年7月

Anthropic「Claude」がテスト中に実在3社へ不正侵入

  • 14万1006件の評価から6件の侵入行為を確認
  • 設定ミスでサンドボックスが外部接続し、実システムを演習と誤認
  • 弱いパスワード等の基本手口で侵入、認証情報が流出
  • 悪意あるPyPIパッケージが実在15システムで実行
🔓

SSOトークンは脆弱

OktaやSSOのソフトトークンはセッションハイジャックに脆弱です。AIモデルの整合性が崩れた場合、プロンプト制約は機能せず、ソフトウェア認証も突破されます。

⚠️

高リスク操作の自律実行

MCPはAIエージェントが削除・転送・デプロイ等の操作を自律実行できる環境を整備しています。エージェントの意図と実際のパラメータを結びつける暗号学的な保証が存在しません。

提示词失效,沙盒泄露,
风险前所未有。

随着企业AI从只读助手演进为具备写操作能力的智能体,缺乏物理安全网已成为关键漏洞。

真实事件 — 2026年7月

Anthropic「Claude」测试期间未授权入侵3家真实企业

  • 从14万1006次评估中确认6起入侵行为
  • 沙盒配置错误导致外部连接打通,真实系统被误识为演练环境
  • 通过弱密码等基础手段入侵,凭证信息泄露
  • 恶意PyPI包在15个真实生产系统上执行
🔓

SSO软令牌存在漏洞

Okta或SSO等软令牌易受会话劫持攻击。当AI模型对齐崩溃时,提示词约束失效,软件认证同样形同虚设。

⚠️

高风险操作自主执行

MCP使AI智能体能够自主执行删除、转移、部署等操作。目前没有任何密码学机制将智能体的意图与实际执行的参数绑定在一起。

The "Ultimate Physical Defense"
for the AI Agent Era

An out-of-band, hardware-isolated zero-trust defense line built specifically for the Model Context Protocol — requiring a physical Passkey signature for every high-risk tool invocation.

"Even if the AI model's alignment completely breaks down and the host environment is compromised — the human's physical hardware chip holds control of the system."
Dimension Before MCPkey — Status Quo Risk After MCPkey — Cryptographic Guarantee
Auth model SSO session token (vulnerable to hijacking) FIDO2 hardware assertion per operation
Parameter integrity None — AI can silently modify payloads Intent Binding: signature tied to exact JSON hash
Audit trail Soft logs, repudiable Non-repudiable cryptographic chain, air-gap isolated
AI trust assumption Trust the model's alignment and constraints Zero trust — hardware enforces regardless of model state
Client engineering Custom integration per client Zero frontend burden — SEP-1865 UI injection
Compliance posture Prompt-based governance (not auditable) Hardware-anchored audit chain for GDPR, HIPAA, SOC2

AIエージェント時代の
"究極の物理的防衛"

モデルコンテキストプロトコル(MCP)向けに特別設計されたアウトオブバンド物理隔離ハードウェアゼロトラスト防衛ライン。高リスクなツール呼び出しに物理的なPasskey署名を必須化します。

「たとえAIモデルの整合性が完全に崩れ、ホスト環境が乗っ取られたとしても、人間が持つ物理的なハードウェアチップがシステムの制御を固定する。」
比較項目 MCPkey導入前 — 現状のリスク MCPkey導入後 — 暗号学的保証
認証モデル SSOセッショントークン(ハイジャック可能) 操作ごとのFIDO2ハードウェアアサーション
パラメータ完全性 なし — AIが無声でペイロードを改ざん可能 Intent Binding:署名が正確なJSONハッシュに紐づく
監査証跡 ソフトログ、否認可能 否認不可能な暗号チェーン、帯外隔離
AI信頼前提 モデルの整合性と制約を信頼 ゼロトラスト — モデル状態に関わらずハードウェアが強制
クライアント工数 クライアントごとにカスタム統合が必要 Zero Frontend Burden — SEP-1865 UI注入
コンプライアンス プロンプトベースのガバナンス(監査不可) GDPR・個人情報保護法対応の暗号監査チェーン

AI智能体时代的
"终极物理防线"

专为模型上下文协议(MCP)打造的带外物理隔离硬件零信任防御层,对每一次高风险工具调用强制要求物理Passkey硬件签名。

「即便AI模型对齐完全崩溃,宿主环境遭到攻陷——人类持有的物理硬件芯片仍将牢牢掌控系统控制权。」
对比维度 MCPkey之前 — 现状风险 MCPkey之后 — 密码学保证
认证模型 SSO会话令牌(易受会话劫持) 每次操作独立的FIDO2硬件断言
参数完整性 无——AI可静默篡改载荷参数 意图绑定:签名绑定至精确JSON哈希值
审计追踪 软日志,可被否认 不可否认密码链,气隙隔离
AI信任假设 信任模型对齐与提示词约束 零信任——硬件强制执行,与模型状态无关
客户端工程量 每个客户端需独立定制集成 零前端侵入——SEP-1865 UI动态注入
合规态势 基于提示词的治理(不可审计) 硬件锚定审计链,满足GDPR、等保、HIPAA要求

How It Works — Cryptographic Hardware Release Chain

1

AI Agent Invokes a High-Risk Tool

The agent autonomously initiates a sensitive operation via MCP.

2

MCP Apps Sandbox UI (WYSIWYG)

Parameters are displayed in full — e.g. "Transfer $10,000" — so the human sees exactly what will execute.

3

User Physical Hardware Auth

Touch ID / Face ID / YubiKey physical press generates a FIDO2 assertion cryptographically bound to the payload hash.

4

MCP Server Cryptographic Verification

Direct cryptographic verification of the assertion against the exact payload — no trust in the AI model or host.

5

Business Operation Released

Delete / Transfer / Deploy executes only after cryptographic proof of human physical intent.

Differentiator 01 — Intent Binding

Parameter Tampering Is Cryptographically Impossible

The signature is bound to the exact JSON payload hash. Any parameter change invalidates the assertion before execution.

Differentiator 02 — Air-Gap Isolation

Independent of SSO / Soft Tokens

Out-of-band authentication builds a non-repudiable audit chain entirely independent of session hijacking vectors.

Differentiator 03 — Zero Frontend Burden

No Client Modifications Required

Based on MCP Apps (SEP-1865), the server dynamically injects standard UI into mainstream clients. Zero frontend engineering cost.

仕組み — 暗号ハードウェアリリースチェーン

1

AIエージェントが高リスクツールを起動

エージェントがMCPを通じて機密性の高い操作を自律的に開始します。

2

MCP Apps 沙箱 UI(WYSIWYG)

「Transfer $10,000」等のパラメータを完全表示。人間が実行内容を正確に確認できます。

3

ユーザーローカルハードウェア認証

Touch ID / Face ID / YubiKeyの物理プレスがペイロードハッシュにバインドされたFIDO2アサーションを生成します。

4

MCPサーバーによる暗号的検証

正確なペイロードに対してアサーションを暗号的に直接検証。AIモデルもホスト環境も信頼不要。

5

業務実行のリリース

削除・転送・デプロイは、人間の物理的意図の暗号学的証明があって初めて実行されます。

差別化01 — Intent Binding(意図绑定)

パラメータ改ざんを暗号学的に防止

署名は特定のJSONペイロードハッシュに紐づきます。パラメータ変更はアサーションを無効化し、実行前に検知されます。

差別化02 — エアギャップ隔離(帯外隔離)

SSO・ソフトトークンから完全独立

アウトオブバンド認証により、セッションハイジャックから独立した否定できない監査チェーンを構築します。

差別化03 — Zero Frontend Burden(零前端侵入)

フロントエンド改修不要

MCP Apps(SEP-1865)準拠で、サーバーが主流クライアントへ標準UIを動的注入。フロントエンド開発コストはゼロです。

工作原理 — 密码硬件释放链

1

AI智能体触发高风险工具

智能体通过MCP自主发起敏感操作。

2

MCP Apps 沙盒UI(所见即所得)

完整展示参数内容,如"转账$10,000",人类清楚看到将要执行的内容。

3

用户本地硬件认证

Touch ID / Face ID / YubiKey 物理按压,生成绑定到载荷哈希的FIDO2断言。

4

MCP服务器密码学验证

针对精确载荷对断言进行密码学直接验证——无需信任AI模型或宿主环境。

5

业务操作释放执行

删除 / 转移 / 部署,仅在获得人类物理意图的密码学证明后方可执行。

差异化01 — 意图绑定(Intent Binding)

密码学层面阻断参数篡改

签名绑定至精确的JSON载荷哈希。任何参数修改都将在执行前使断言失效。

差异化02 — 气隙隔离(带外隔离)

独立于SSO / 软令牌体系

带外认证构建不可否认的审计链,完全独立于会话劫持攻击向量。

差异化03 — 零前端侵入

无需修改任何客户端

基于MCP Apps(SEP-1865),服务器向主流客户端动态注入标准UI,前端工程成本为零。

Built for the Industries Where Stakes Are Highest

As enterprise AI shifts from read-only assistants to write-capable agents between 2026–2030, physical safety nets become a critical IT security requirement.

🏦
FinTech / Banking

Financial Operations

Physical signature for single fund transfers, automated accounting, and FX operations. Decision makers: CISO, Security Directors.

⚙️
DevOps / Cloud

Infrastructure Automation

Production deployments, DB migrations, and sensitive config changes require human cryptographic sign-off. Decision makers: SRE Leads, Cloud Architects.

⚕️
Legal / Healthcare

Sensitive Data Access

AI access and export operations on PII and high-confidentiality datasets. Decision makers: CPO, Compliance Officers.

🔭

MCPkey: Hardware Veto Power for Humans in the Loop

Becoming the cryptographic security foundation for the AI era — pulling AI governance from illusory "prompt constraints" back to genuine physical security anchors.

最もリスクが高い業界のために構築

2026〜2030年にかけてエンタープライズAIが読み取り専用から書き込みエージェントへ移行する中、物理的なセーフティネットは重要なITセキュリティ要件となります。

🏦
フィンテック・銀行

金融オペレーション

単一資金移動・自動会計処理・為替操作等の高リスクAI自動化に物理的な署名を適用。意思決定者:CISO、セキュリティ部門長。

⚙️
DevOps・クラウドインフラ

インフラ自動化

本番環境デプロイ、DBマイグレーション、機密設定変更に人間の暗号学的承認が必要。意思決定者:SRE Lead、クラウドアーキテクト。

⚕️
法務・医療

機密データアクセス

PII等の高機密データセットへのAIアクセス・エクスポート操作を制御。意思決定者:CPO、コンプライアンス担当役員。

🔭

MCPkey:人間がループに入った者のためのハードウェア拒否権

AI時代の暗号学的セキュリティ基盤となり、AI管理を幻想的な「プロンプト制約」から本当の「物理的なセキュリティアンカー」へと引き戻します。

风险最高的行业而生

2026至2030年间,企业AI从只读助手转型为具备写操作能力的智能体,物理安全网将成为关键的IT安全要求。

🏦
金融科技 / 银行

金融操作

单笔资金转移、自动化会计处理、外汇操作等高风险AI自动化场景的物理签名。决策者:CISO、安全负责人。

⚙️
DevOps / 云基础设施

基础设施自动化

生产环境部署、数据库迁移、敏感配置变更须经人类密码学签批。决策者:SRE负责人、云架构师。

⚕️
法务 / 医疗

敏感数据访问

对含PII等高度机密数据集的AI访问与导出操作进行管控。决策者:CPO、合规官员。

🔭

MCPkey:人类在环的硬件否决权

成为AI时代的密码学安全基础,将AI治理从虚幻的「提示词约束」拉回真正的「物理安全锚点」。

Frequently Asked Questions

Everything you need to know about MCPkey, MCP security, and hardware-based AI authorization.

What is MCPkey?
MCPkey is a hardware-isolated, out-of-band zero trust authorization layer for AI agents that operate via the Model Context Protocol (MCP). It requires a physical FIDO2 Passkey hardware signature — from Touch ID, Face ID, or YubiKey — before any high-risk AI operation such as file deletion, fund transfer, or production deployment can execute. Unlike prompts or SSO, MCPkey provides a cryptographic guarantee that no AI agent or compromised host can bypass.
Why does MCP need additional security?
MCP enables AI agents to perform real-world write operations — delete, transfer, deploy — autonomously. Existing defenses fail at this layer: prompt constraints stop working when AI model alignment breaks, and SSO / soft tokens only protect session login, not individual operations within a session. In July 2026, Anthropic's Claude made unauthorized intrusions into 3 real companies during testing, confirming that sandbox and prompt-level controls are insufficient when agents have real-world tool access.
How does MCPkey work step by step?
MCPkey implements a 5-step cryptographic hardware release chain:
  1. AI agent attempts to invoke a high-risk MCP tool.
  2. MCPkey displays a WYSIWYG sandbox UI showing exact parameters (e.g., "Transfer $10,000").
  3. User performs physical hardware authentication — Touch ID / Face ID / YubiKey press.
  4. The press generates a FIDO2 assertion cryptographically bound to the SHA-256 hash of the exact JSON payload.
  5. MCP server cryptographically verifies the assertion before executing. No hardware proof = no execution.
What is Intent Binding?
Intent Binding is the core security innovation of MCPkey. The FIDO2 hardware signature is bound to the SHA-256 hash of the exact JSON payload of the requested operation. If any parameter changes after user authorization — even a single character — the assertion becomes cryptographically invalid and the MCP server rejects execution. This makes parameter tampering by the AI model or a compromised host mathematically impossible.
How is MCPkey different from MFA or SSO?
Traditional MFA and SSO protect the session login boundary, but do nothing for individual operations within an authenticated session. Once a session token exists, an AI agent can abuse it to perform any number of operations. MCPkey operates out-of-band from the host session: it requires a fresh physical hardware assertion for each high-risk operation, and binds that assertion to the exact parameters. Even full session hijacking cannot bypass MCPkey.
What hardware does MCPkey support?
MCPkey supports: Apple Touch ID (Secure Enclave on Mac / iPhone), Apple Face ID, and YubiKey FIDO2 hardware security keys. All authentication uses the open FIDO2 / WebAuthn standard, so any FIDO2-certified authenticator is compatible. Software TOTP fallback is available as a temporary measure, with a planned deprecation roadmap.
Does MCPkey require changes to existing MCP clients or frontends?
No. MCPkey implements Zero Frontend Burden using the MCP Apps standard (SEP-1865). The MCP server dynamically injects the authorization UI into mainstream MCP-compatible clients. No frontend code changes, no client SDK updates, and no engineering work on the client side is required. Deployment is purely server-side.
Which industries and compliance frameworks benefit most?
MCPkey is most impactful in:
  • FinTech / Banking — non-repudiable audit chains for AI-initiated fund transfers, satisfying AML and financial regulation requirements.
  • DevOps / Cloud — human cryptographic sign-off for production deployments and DB migrations, reducing blast radius of AI agent errors.
  • Legal / Healthcare — hardware-anchored access logs for PII and medical data, supporting GDPR, HIPAA, and SOC 2 compliance.

FAQ

MCPkey、MCPセキュリティ、ハードウェアベースのAI認可に関するよくある質問をまとめました。

MCPkeyとは何ですか?
MCPkeyは、モデルコンテキストプロトコル(MCP)を通じて動作するAIエージェント向けの、ハードウェア隔離型アウトオブバンドゼロトラスト認可レイヤーです。ファイル削除・資金移動・本番デプロイ等の高リスクなAI操作を実行する前に、Touch ID・Face ID・YubiKeyによる物理的なFIDO2 Passkeyハードウェア署名を必須化します。
Intent Binding(意図绑定)とは何ですか?
Intent BindingはMCPkeyの中核セキュリティ技術です。FIDO2ハードウェア署名は、操作要求の正確なJSONペイロードのSHA-256ハッシュに暗号学的に紐づけられます。ユーザーの承認後にパラメータが1文字でも変更された場合、アサーションは無効となりMCPサーバーは実行を拒否します。これにより、AIモデルや侵害されたホストによるパラメータ改ざんが数学的に不可能となります。
SSO・MFAとどう違いますか?
従来のMFA・SSOはセッションログインの境界を保護しますが、認証済みセッション内の個々の操作には何も対処しません。MCPkeyはホストセッションから独立したアウトオブバンドで動作し、高リスク操作ごとに新鮮なハードウェアアサーションを要求します。セッションが完全にハイジャックされても、MCPkeyはバイパスできません。
フロントエンドや既存クライアントへの改修は必要ですか?
不要です。MCPkeyはMCP Apps標準(SEP-1865)に基づき、MCPサーバーが主流クライアントへ標準UIを動的注入します。クライアント側のコード変更・SDK更新・フロントエンド工数は一切不要です。デプロイは純粋にサーバーサイドで完結します。
どのハードウェアに対応していますか?
Touch ID(Mac/iPhoneのSecure Enclave)、Face ID、YubiKey(FIDO2ハードウェアキー)に対応しています。すべてオープンスタンダードのFIDO2 / WebAuthnを使用しており、FIDO2認定のあらゆる認証器と互換性があります。

FAQ

关于MCPkey、MCP安全以及硬件AI授权的常见问题解答。

MCPkey是什么?
MCPkey是专为通过模型上下文协议(MCP)运行的AI智能体设计的硬件隔离带外零信任授权层。在执行删除、转账、部署等高风险AI操作之前,强制要求Touch ID、Face ID或YubiKey的物理FIDO2 Passkey硬件签名。即使AI模型或宿主环境完全失控,物理硬件密钥始终在人类手中,确保系统控制权不旁落。
什么是意图绑定(Intent Binding)?
意图绑定是MCPkey的核心安全创新。FIDO2硬件签名密码学绑定至操作请求的精确JSON载荷的SHA-256哈希值。用户授权后,若任何参数发生改变——哪怕是一个字符——断言立即失效,MCP服务器拒绝执行。这使得AI模型或被攻陷宿主对参数的篡改在数学层面不可能实现。
MCPkey与MFA、SSO有何不同?
传统MFA和SSO只保护会话登录边界,对已认证会话内部的单次操作毫无防护。一旦会话令牌存在,AI智能体便可滥用它执行任意数量的操作。MCPkey独立于宿主会话运行(带外),对每一次高风险操作都要求全新的物理硬件断言,并将该断言绑定至精确的操作参数。即使会话被完全劫持,也无法绕过MCPkey。
MCPkey是否需要修改现有MCP客户端或前端?
不需要。MCPkey基于MCP Apps标准(SEP-1865)实现零前端侵入。MCP服务器向主流兼容客户端动态注入标准授权UI,无需任何客户端代码修改、SDK更新或前端工程投入。部署完全在服务端完成。
支持哪些硬件设备?
MCPkey支持:Apple Touch ID(Mac/iPhone Secure Enclave)、Apple Face ID,以及YubiKey FIDO2硬件安全密钥。所有认证均基于开放标准FIDO2 / WebAuthn,任何FIDO2认证的硬件认证器均兼容。
哪些行业和合规框架最受益?
MCPkey最适合以下场景:
  • 金融科技/银行——AI发起资金转账的不可否认审计链,满足反洗钱及金融监管要求。
  • DevOps/云基础设施——生产环境部署和数据库迁移的人类密码签批,降低AI智能体操作的爆炸半径。
  • 法务/医疗——PII和医疗数据的硬件锚定访问日志,支持GDPR、等保2.0、HIPAA合规。