Kong AI Gateway Used to Add Per-Tool Access Controls to Meta's Muse Code Agent

A developer tested whether Meta's terminal coding agent, Muse Code, could autonomously handle the first stage of an incident investigation by connecting it to operational tools via remote MCP servers. A key concern was that Muse Code's MCP tools run outside the client's sandbox and approval mechanisms, meaning the agent could execute high-risk actions like rolling back production deployments without any client-side prompt. To address this, the developer routed the agent through Kong AI Gateway 2.0, which converts a REST API into MCP tools and enforces per-tool access control lists based on caller identity. Two identities were configured — an investigator and an operator — where the investigator could open incidents but was entirely hidden from the rollback tool, not merely blocked from using it. The full setup, including gateway configuration, a mock ops API, and real agent transcripts, has been published on GitHub.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in