· Platform
The MCP gateway: agents reach servers only through Realm
One Streamable HTTP gateway inside realm-server. Every MCP call an agent makes goes through it, which is how the credential stays out of the agent.
The usual arrangement gives each agent its own MCP configuration and its own copy of every token. That is one credential store per harness, and no single place that can say what was called.
Realm runs the gateway. Servers are configured once, connected once, and every agent reaches them through Realm, so the agent never receives the token and there is one call log rather than four.
How it is exposed
agent -> realm-server (gateway) -> MCP server
^
credentials, scoping, call logThe gateway listens on port 0 and reports the port it was given, so nothing collides with whatever else is running. Tools are scoped per space: a space that has not asked for a provider does not see it.