Strongest existing alignment for credentials, schemas, egress, and lifecycle.
ACP · MCP · MULTI-TENANT
The missing boundary is ownership.
MCP exists in the runtime. rc.2 owns it at deployment time, not ACP Session time.
deployment bootMCP plugin
Host registryACP session/newfresh Agent
inherits toolsclient mcpServersrejected
rc.2 contract
Connection is not contribution.
Stdio or Streamable HTTP discovery registers one Host-scoped tool generation.
A fresh Agent receives the fixed composition but cannot mount a new MCP row.
Non-empty input fails before a Session can claim an external server.
Architecture choice
Put routing behind a real trust boundary.
A future Session selects reviewed identities, never arbitrary URLs or headers.
One deployment endpoint enforces tenant policy and remote execution.
Requires SSRF controls, quotas, Agent-scoped tools, and complete disposal.
Teardown
One Session must release one complete graph.
Reject new calls, settle in-flight work, stop reconnect timers, unregister tools, close transport, then dispose the Agent.
Current safe pathreviewed deployment gatewaytenant identity stays outside model-controlled arguments
Primary evidence