# MCP Gateway

A governed checkpoint every tool connection passes through (authenticated, policy-checked, and logged) so credentials stay central and unapproved servers can't connect.

Learn more: [MCP Gateway: Build vs Buy](/content/learn/mcp-gateway-build-vs-buy/index.html)

Part of [the Agent Control Fabric](/content/platform/index.html): Highflame's identity, policy, and enforcement substrate for AI agents.

## Keep exploring the glossary.

[**Mission drift** \
When a non-deterministic agent gradually diverges from its intended task. Tracked at runtime so it can be contained before consequences land.\
Read →](/content/glossary/mission-drift/index.html) 
[**Non-human identity (NHI)** \
Identities belonging to machines, services, and agents rather than people. Agents are the fastest-growing and least-governed class of NHI.\
Read →](/content/glossary/nhi/index.html) 
[**On-behalf-of (OBO) chain** \
The unbroken provenance recorded on a credential (who authorized the action, what scope was granted, and how deep the delegation goes) so an audit walks back to a human.\
Read →](/content/glossary/obo-chain/index.html) 
[**Prompt injection** \
An attack that manipulates an agent through crafted input (in a prompt, a tool result, or retrieved content) to make it act against policy.\
Read →](/content/glossary/prompt-injection/index.html) 
[**Red teaming** \
Continuous adversarial testing of AI systems (jailbreaks, extraction, manipulation) with findings turned into enforcement policy and re-scanned to prove the fix.\
Read →](/content/glossary/red-teaming/index.html) 
[**RFC 8693 (token exchange)** \
The standard that lets one token be exchanged for another with attenuated scope: the basis for verifiable agent-to-agent delegation.\
Read →](/content/glossary/rfc-8693/index.html)
