Enterprise authorization
Stacklok Enterprise
Enterprise authorization lets cluster admins define reusable MCP roles and lets namespace admins grant those roles on the servers they manage.
Where to start
Introduction to enterprise authorization
Express MCP access in RBAC terms and let the operator compile it to Cedar, so role-based authorization scales across an MCP fleet.
Quickstart - GitHub MCP with Entra ID
Pair Microsoft Entra ID with the GitHub MCP server and enforce role-based authorization with a compiled ToolhiveAuthorizationPolicy.
Delegate authorization by namespace
Let namespace administrators grant approved roles on the MCP servers they manage.
CRD reference
For the full field reference of each resource, see ClusterPlatformRole, ClusterPlatformRoleBinding, PlatformRoleBinding, and ToolhiveAuthorizationPolicy.