Skip to main content

AI Gateway and MCP architecture

System topology​

The public endpoint is AIRS. clippy-mcp is a ClusterIP-only service: AIRS reaches it through the registered upstream, but there is no public Kubernetes ingress. The application can call it directly inside the cluster and mints its own clippy-mcp-client token.

User-bound chat request​

A browser turn. The login token never leaves the app; each route gets a token exchanged from it.

Org-level JWKS request​

This is the production external request. The JWT has both Portkey organization/workspace claims and the Clippy permission claims.

There are two cryptographic validations of the identity token: at AIRS and at clippy-mcp. The second check is deliberate defense in depth, not duplicate gateway authentication.

Workspace key plus JWT Validator Guardrail​

This is the customer pattern when the IdP token does not carry Portkey organization claims.

The two header values are different in this mode. $JWT is not a gateway key unless it carries the configured Portkey organization claims.

Clippy Chat internal request​

The web app does not send its browser/user session token to MCP. The server-side application mints a scoped machine token, caches it until 30 seconds before expiry, and supplies it directly to the internal MCP server.

Authorization decision​

Trust boundaries​

BoundaryTrusted inputRejected input
Keycloak token endpointRegistered confidential client and secretWrong/disabled client, wrong secret
AIRS org authenticationGateway key or verified org-claim JWTMissing/malformed/wrong-org credential
AIRS MCP registrationToken matching exact server policyWrong audience/client/scope/workspace
clippy-mcpForwarded RS256 bearer matching environment policyMissing, duplicate, malformed, expired, or mismatched bearer
Tool layerAuthorized JSON-RPC method and validated argumentsUnknown method/tool or invalid arguments

Deployment ownership​

ComponentSource of truthDeployment
Clippy app and MCP serverClippy ForgejoForgejo CI builds immutable Harbor images; Argo CD applies manifests
Keycloak realm/client projectionTalos cluster repositoryDeclarative stack projection and lifecycle scripts
AIRS and MCP registrationsTalos cluster repositoryHelm/Argo plus guarded cutover scripts
Public Docusaurus docsClippy Forgejo, mirrored to GitHubGitHub Pages workflow on mirrored main

For exact values and test expectations, continue to E2E testing.