主なポイント
- Every MCP server call requires credentials. Without proper secret management, those credentials are stored in plaintext, visible to anyone with database access.
- When a secret is compromised, most organizations cannot trace who was affected and what they could access.
- Boomi’s MCP gateway handles secret management at the protocol layer: encryption at rest, integration with your existing secret manager, admin-controlled access by group, and automatic propagation when values change.
Managing API keys and credentials has always been a problem. For enterprise teams deploying AI agents at scale, MCP makes it significantly larger. Every outbound call from an MCP server carries secrets: API keys, database passwords, and OAuth tokens. As the relay between your AI agents and production systems, MCP servers are frequently managing privileged access to critical software.
According to Astrix Security’s 2025 research, 88% of MCP servers require credentials to operate, and 53% rely on static API keys or personal access tokens, long-lived credentials that require manual rotation to stay secure. Token mismanagement and secret exposure rank #1 on the OWASP MCP Top 10.
What current MCP security guidance does not cover is the organizational problem: what happens when you are not managing one MCP server for one team, but dozens of servers across hundreds of users, with different access levels, connected to systems that carry sensitive data?
That is the enterprise problem, and it is where MCP without a proper secret management approach breaks down entirely.
How MCP handles API keys and secrets today
When a user loads an MCP server, they provide configuration. Some of it is generic. Some of it is sensitive: API keys, tokens, and connection strings. That sensitive data has to live somewhere. In most MCP implementations, it lives in a database, mapped to the server configuration.
A DevOps engineer with database access can query that table and read the values in plaintext. If a user has high-privilege credentials mapped to a server, that engineer can act on their behalf, against their systems, without that user ever knowing.
Before an MCP gateway is in place, a user’s API key is typically stored as plaintext in the database or locally on the machine, mapped to their server configuration. Any engineer, AI agent, or malicious actor with database access could read it and act on that user’s behalf without their knowledge.
The rest of this article walks through the rules of enterprise MCP secret management, the use cases that demonstrate them, and how Boomi MCP Gateway applies each one.
Rule #1: Secrets must be encrypted at rest
Plaintext credentials in a database are an exposure surface. Anyone with read access can pull every credential in the system. Encryption at rest means the stored value is unreadable without a key held separately from the database.
How MCP Gateway applies this
The database stores only an encrypted value, unreadable without the encryption key that the DevOps team provisions at installation. At runtime, MCP Gateway decrypts the value in memory for the authenticated user, injects it into the connection, and discards it immediately. The decrypted value is never logged, never written to disk, and never persists beyond the active session.
One important operational note: the encryption key is provisioned by the DevOps team at installation time. If that key is lost, every encrypted value in the database becomes irrecoverable, and the organization would need to reconfigure from scratch. Treat the provisioning key with the same rigor as any production secret.
| MCP Configuration Risk | Consequence at Scale |
| Plaintext secrets in the database | Any engineer with database access can read credential values and impersonate users. |
| No centralized visibility | When secrets are managed per-server and per-user, there is no traceable credential map. |
| Manual API key rotation | Rotating credentials across thousands of instances means tracking down every place a secret was used. |
| Over-broad access grants | A single high-privilege credential visible across the organization means one compromised account is an organization-wide incident. |
Rule #2: Credentials must be scoped by identity, not just hidden
Hiding credential visibility within a UI is not enough to secure privileges if the value can still be surfaced by a user or agent. Credential security means that it cannot be fetched outside its intended scope, even if someone knows it exists.
With Boomi MCP Gateway, an agent has the same access privileges as the user running it, verifying encrypted credentials using tools like OAuth and user-based access control. This way, agents are able to access the privileges they require without storing or exchanging secrets or passwords in plaintext.
4 Ways MCP Gateway manages MCP secrets and API keys
Identity management in Boomi MCP Gateway operates in four modes:
Local value entry. A user provides a credential directly, which Boomi encrypts and resolves at runtime. The value does not persist beyond the active session.
Environment-based injection. Environment variables propagate down to the MCP servers that need them. Admins map environment variables to server parameters, which resolve to the right value in each deployment context: dev, staging, production, per-region, or per-tenant.
Load from Secrets. Administrators control secrets and provision them from a centralized governance layer. The user never sees the underlying value, instead using their integrated enterprise vault.
OAuth token management. For MCP servers that authenticate via OAuth, MCP Gateway passes the token securely and refreshes it automatically. Users authenticate once and keep uninterrupted access without repeated login prompts.
For enterprises running an MCP gateway at scale, these management modes determine whether credential management is a manual operation or part of a centralized AI governance approach. When an R&D group and an ops group both need access to the same production database, the admin assigns that secret to both profiles once. When the password rotates, both teams pick up the new value automatically, with no coordination required between them.
Different profiles can be mapped to different references for the same field. A sales team connecting to a CRM server gets read-only credentials. An engineering team connecting to the same server gets write access with a higher-privilege key. The admin manages both references centrally. Each user selects the reference that applies to their context, and the right credentials are injected at runtime.
What Enterprise MCP Governance Requires
- Encryption at rest: Secrets are encrypted using a key provisioned by the DevOps team at installation. The database stores only the encrypted value, and the decrypted value is never logged, written to disk, or persisted beyond the active session.
- Observability and incident response: Secrets are assigned to profiles and groups. If a secret is compromised, an admin identifies exactly which users were affected and can revoke access immediately. If a secret assigned to a profile is renamed or removed in the secret manager, the admin is notified in the dashboard before it interrupts users’ connections. Organizations running more than one secret manager can see at a glance which vault each secret is pulled from, making it straightforward to audit coverage across providers.
- Automatic credential refresh: When a value is updated in the connected secret manager, every MCP Gateway instance picks up the new credentials on the next connection. No manual API key rotation required, and no stale credentials in production.
- Compliance: Group-level secret assignment creates a clear record of who has access to what. Every secret access event is logged, giving security teams a complete audit trail for compliance review.
- Operational reliability at scale: Admins configure once at the profile level, and users select from named references. When pods fall and restart in cloud Kubernetes environments, MCP Gateway refreshes the correct secrets automatically based on group assignment.
Trust Boomi to Help You Govern MCP Servers Across the Enterprise
Boomi provides you with a control tower for MCP, going beyond just connecting systems by making them securely consumable for agents and applying policy, identity, access control, and audit trails across every managed asset. Boomi turns your company’s existing integrations, APIs, legacy applications, and data into discoverable tools with no custom builds and no re-platforming, just one-click enablement.
With Boomi Connect, this control goes even further: you get a managed MCP connector service that gives knowledge workers real-time access to enterprise applications from inside the AI tools they regularly use, whether that’s Claude, Copilot, Gemini, or any MCP client, while providing IT the control and visibility to allow it.
Boomi brings together:
- 1,000+ pre-built MCP connectors available across every major enterprise application
- An admin control center, where IT provisions specific users and groups with exactly the access they need
- Always-on, CISO-ready auditing, logging every tool call, user, action, timestamp, and outcome, from the first call with no configuration required
- OAuth exchange, token handling, and refresh cycles, with support for organization-level credentials as well as per-user identity through OAuth pass-through
- Context-rich metadata to feed agents so they understand how to work with complex business processes
The Boomi catalog is vendor-agnostic, unifying servers from its own registry, third parties, and from the Official MCP Registry into one governed repository. Plus, as Boomi is the only platform with a bidirectional link to that official registry, it can both consume from and publish to the open standard.
Boomi also handles the full lifecycle with scoped control all the way from creation through retirement:
- Servers register automatically
- Third-party servers bulk-import into a production-ready catalog
- Subregistries handle team-level access
- Real-time monitoring with anomaly detection watches behavior in flight
And because the catalog is native to Boomi Agentstudio, you can build and govern together, with no context switching, ensuring adoption and safety go hand in hand instead of pulling against each other.
Are you tired of just guessing at what your agents can reach? Check out Boomi Agent Control Plane to discover how to activate AI instantly, maintain full control, and ensure compliance.