DKDKCISSPSearch
AI SecurityDEVELOPING

Postman adds security controls for AI agents, APIs, and MCP servers - Help Net Security

Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

DKCISSP News DeskHelp Net Security29 Sept 2026, 7:10 pm
Postman adds security controls for AI agents, APIs, and MCP servers - Help Net Security
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.

With Fabric Gateway, organizations can securely connect AI agents to their APIs while centrally controlling what agents can discover, access, and do without introducing fragmented tools or one-off integrations.

As enterprises rapidly deploy AI agents, they are discovering that existing infrastructure was designed for applications and human users, not autonomous systems that continuously collaborate across APIs.

The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients.

Fabric Gateway provides this control layer that lets enterprises securely connect AI agents to the APIs, tools, and services that power their businesses.” With Postman Fabric Gateway, organizations can route, govern, and observe LLMs, MCP servers, agents, and internal APIs through one gateway, deployed inside their own cloud.

With the stolen credentials, the attacker can request a valid access token from the real login service.

If your agents cannot see or securely access your APIs, your business will become irrelevant,” said Abhinav Asthana , CEO of Postman.

According to Gartner, “the rise of AI workloads will render the capabilities of existing API gateways outdated, prompting 80% of organizations to replace or significantly supplement them by 2029.” Furthermore, “as AI agents proliferate, robust support for emerging protocols, such as model context protocol (MCP) and agent-to-agent (A2A) communications, is essential to prevent unauthorized or unmanaged AI interactions.” “We have long predicted that every company would become API-first, but the rise of agentic AI has turned this into a mandate.

Cycode, the security firm that reported the flaw , demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted.

What happened

Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.

What changed

With Fabric Gateway, organizations can securely connect AI agents to their APIs while centrally controlling what agents can discover, access, and do without introducing fragmented tools or one-off integrations.

As enterprises rapidly deploy AI agents, they are discovering that existing infrastructure was designed for applications and human users, not autonomous systems that continuously collaborate across APIs.

Who is affected

The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients.

Fabric Gateway provides this control layer that lets enterprises securely connect AI agents to the APIs, tools, and services that power their businesses.” With Postman Fabric Gateway, organizations can route, govern, and observe LLMs, MCP servers, agents, and internal APIs through one gateway, deployed inside their own cloud.

Why it matters

With the stolen credentials, the attacker can request a valid access token from the real login service.

If your agents cannot see or securely access your APIs, your business will become irrelevant,” said Abhinav Asthana , CEO of Postman.

Technical details

According to Gartner, “the rise of AI workloads will render the capabilities of existing API gateways outdated, prompting 80% of organizations to replace or significantly supplement them by 2029.” Furthermore, “as AI agents proliferate, robust support for emerging protocols, such as model context protocol (MCP) and agent-to-agent (A2A) communications, is essential to prevent unauthorized or unmanaged AI interactions.” “We have long predicted that every company would become API-first, but the rise of agentic AI has turned this into a mandate.

Cycode, the security firm that reported the flaw , demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted.

An application is affected if it uses the SDK as an MCP client over HTTP with one of the OAuth providers OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated 1.x RFC7523OAuthClientProvider, and it can connect to a server it does not fully control while holding credentials for a real login service.

Response

Inside the applications, the same agent queries customer records, exports data, and updates entitlements.

Attribution

Help Net Security: Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents , LLMs, and MCP servers discover and interact with APIs, tools, and other agents.

The Hacker News: A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.

The Hacker News: AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am