The Multi-Tenant Isolation Challenge in AI Tooling
In multi-tenant B2B SaaS platforms (such as customer support automation, CRM agents, or legal workflows), thousands of autonomous AI agents operate on behalf of distinct tenant organizations. If an MCP server relies solely on system prompt instructions to maintain tenant boundaries, an attacker can use indirect prompt injection to force an agent to inspect data or dispatch emails from another tenant’s domain.
Enterprise multi-tenant MCP architecture requires hardware-level credential isolation and cryptographic tenant context injection at the HTTP transport layer before any tool logic executes.
1. Tenant Context Extraction in Streamable HTTP Handlers
In streamable HTTP MCP servers, tenant identity is extracted from signed JWT bearer headers and passed into dynamic tool execution handlers.
import { McpServer } from '@modelcontextprotocol/server';
import { z } from 'zod';
export function createTenantScopedServer(orgId: string, allowedDomains: string[]) {
const server = new McpServer({
name: `sadasend-tenant-${orgId}`,
version: '2.0.0',
});
server.tool(
'send_tenant_email',
'Dispatches email within the organization scope.',
{ to: z.string().email(), subject: z.string(), body: z.string() },
async ({ to, subject, body }) => {
// 1. Enforce strict tenant allowlist partition
const domain = to.split('@')[1];
if (!allowedDomains.includes(domain)) {
return {
isError: true,
content: [{ type: 'text', text: `Security Refusal: ${domain} is outside Org ${orgId} allowlist.` }],
};
}
// 2. Dispatch using tenant-specific scoped key
const res = await fetch('https://api.sadasend.com/emails', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.SADASEND_MASTER_KEY}`,
'X-Tenant-Org-ID': orgId,
'Content-Type': 'application/json',
},
body: JSON.stringify({ to, subject, text: body }),
});
const data = await res.json();
return { content: [{ type: 'text', text: `Queued with ID: ${data.id}` }] };
}
);
return server;
}Multi-Tenant Security Architecture Comparison
| Security Strategy | Cross-Tenant Leak Risk | Scalability | Operational Overhead |
|---|---|---|---|
| Prompt-Level Guardrails | Extremely High (Vulnerable to injection) | High | Low |
| Dedicated Subprocesses per Tenant | Low (Isolated memory) | Extremely Low (OOM crashes) | High |
| Stateless JWT Tenant Routing | Zero (Cryptographic containment) | High (Millions of agents) | Minimal |
Core Multi-Tenant Architectural Requirements
- Dynamic Rate Limiting: Prevent a single high-volume tenant from exhausting cluster egress capacity using Redis token buckets.
- Partitioned Audit Logging: Every JSON-RPC tool invocation must be tagged with OrgId, AgentId, and IP address for compliance.
- Cryptographic Data Isolation: Ensure tenant API keys cannot be read across worker memory spaces in shared container environments.
Building AI agents that send email?
Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.