ACP · MCP · MULTI-TENANT

The missing boundary is ownership.

MCP exists in the runtime. rc.2 owns it at deployment time, not ACP Session time.

rc.2 contract

Connection is not contribution.

DSH MCP clientDeployment-owned

Stdio or Streamable HTTP discovery registers one Host-scoped tool generation.

ACP SessionAgent-owned

A fresh Agent receives the fixed composition but cannot mount a new MCP row.

ACP mcpServersHard-rejected

Non-empty input fails before a Session can claim an external server.

Architecture choice

Put routing behind a real trust boundary.

01Host per tenant

Strongest existing alignment for credentials, schemas, egress, and lifecycle.

02Named allowlist

A future Session selects reviewed identities, never arbitrary URLs or headers.

03MCP gateway

One deployment endpoint enforces tenant policy and remote execution.

04Direct HTTP

Requires SSRF controls, quotas, Agent-scoped tools, and complete disposal.

Teardown

One Session must release one complete graph.

Reject new calls, settle in-flight work, stop reconnect timers, unregister tools, close transport, then dispose the Agent.

Current safe pathreviewed deployment gatewaytenant identity stays outside model-controlled arguments

Primary evidence

Read the contracts.