Skip to content
Writing
MCPMulti-TenantArchitectureSaaS

Multi-Tenant MCP Architecture for SaaS Applications: Partitioning Agent Contexts

Serving thousands of AI agents across enterprise tenants requires strict context partitioning. Learn how to architect multi-tenant MCP servers with zero cross-tenant data leakage.

The Multi-Tenant Isolation Challenge in AI Tooling

In multi-tenant B2B SaaS platforms (such as customer support automation, CRM agents, or legal workflows), thousands of autonomous AI agents operate on behalf of distinct tenant organizations. If an MCP server relies solely on system prompt instructions to maintain tenant boundaries, an attacker can use indirect prompt injection to force an agent to inspect data or dispatch emails from another tenant’s domain.

Enterprise multi-tenant MCP architecture requires hardware-level credential isolation and cryptographic tenant context injection at the HTTP transport layer before any tool logic executes.

1. Tenant Context Extraction in Streamable HTTP Handlers

In streamable HTTP MCP servers, tenant identity is extracted from signed JWT bearer headers and passed into dynamic tool execution handlers.

TYPESCRIPT
import { McpServer } from '@modelcontextprotocol/server';
import { z } from 'zod';

export function createTenantScopedServer(orgId: string, allowedDomains: string[]) {
  const server = new McpServer({
    name: `sadasend-tenant-${orgId}`,
    version: '2.0.0',
  });

  server.tool(
    'send_tenant_email',
    'Dispatches email within the organization scope.',
    { to: z.string().email(), subject: z.string(), body: z.string() },
    async ({ to, subject, body }) => {
      // 1. Enforce strict tenant allowlist partition
      const domain = to.split('@')[1];
      if (!allowedDomains.includes(domain)) {
        return {
          isError: true,
          content: [{ type: 'text', text: `Security Refusal: ${domain} is outside Org ${orgId} allowlist.` }],
        };
      }

      // 2. Dispatch using tenant-specific scoped key
      const res = await fetch('https://api.sadasend.com/emails', {
        method: 'POST',
        headers: {
          Authorization: `Bearer ${process.env.SADASEND_MASTER_KEY}`,
          'X-Tenant-Org-ID': orgId,
          'Content-Type': 'application/json',
        },
        body: JSON.stringify({ to, subject, text: body }),
      });

      const data = await res.json();
      return { content: [{ type: 'text', text: `Queued with ID: ${data.id}` }] };
    }
  );

  return server;
}

Multi-Tenant Security Architecture Comparison

Security StrategyCross-Tenant Leak RiskScalabilityOperational Overhead
Prompt-Level GuardrailsExtremely High (Vulnerable to injection)HighLow
Dedicated Subprocesses per TenantLow (Isolated memory)Extremely Low (OOM crashes)High
Stateless JWT Tenant RoutingZero (Cryptographic containment)High (Millions of agents)Minimal

Core Multi-Tenant Architectural Requirements

  • Dynamic Rate Limiting: Prevent a single high-volume tenant from exhausting cluster egress capacity using Redis token buckets.
  • Partitioned Audit Logging: Every JSON-RPC tool invocation must be tagged with OrgId, AgentId, and IP address for compliance.
  • Cryptographic Data Isolation: Ensure tenant API keys cannot be read across worker memory spaces in shared container environments.
Free plan

Building AI agents that send email?

Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.