Use Case: Propagate User Identity for MCP Tool Invocations

This use case provides an overview of how OAuth JWT user assertion is used to securely propagate the same user identity and access credentials across the MCP gateway, MCP server, and agentic AI tool-registered integrations to the endpoint system. Identity propagation is supported with the OAuth using JWT User Assertion security policy.

Overview

This use case provides a walk through of the following MCP gateway configuration:
  • Two integrations are registered as agentic AI tools.
    • JWT_UpdateSecurityPolicyOfAConnection integration: Calls the Developer API for Oracle Integration 3 to update the security policy of a specific connection in a service instance.
    • AUTOMATION_JWT_IDCS_GET_INTEGRATIONS_IDENTITYPROPAGATION integration: Calls the Developer API for Oracle Integration 3 to list the integrations in a specific service instance.
  • A REST Adapter invoke connection used in the integrations is configured with the OAuth using JWT User Assertion security policy.
  • The agentic AI tools are discovered during MCP server creation and configuration. The MCP server is also configured to use JWT user assertion security.
  • The MCP gateway is created and configured to manage the MCP server (and its discovered agentic AI tool-registered integrations).
  • The MCP gateway is run. During design-time configuration, several different user names are specified. However, the user running the MCP gateway is securely propagated across the MCP gateway, MCP server, and agentic AI tool-registered integrations to the endpoint system.


The Oracle Integration “JWTUserAssertion-MVRP” Design page shows two integrations and three REST Adapter connections. The invoke connection is configured to use JWT user assertion.

Prerequisites

  • Create or use an existing confidential application configured with the JWT assertion grant type in the Oracle Cloud Console. The information created with the confidential application is required for adapter and MCP server configuration. For creation instructions, see Use OAuth 2.0 Grants in Identity Domain Environments in Using the REST Adapter with Oracle Integration 3.
  • Manually create a signing key to upload on the Certificates page. See Upload a Certificate to Connect with External Services in Using the REST Adapter with Oracle Integration 3. The service provider typically provides instructions on how to generate the signing keys and the format. For an example, see Required Keys and OCIDs.
  • Create the JWT header and JWT payload JSON files. You upload both files on the Connections page when configuring the REST Adapter invoke connection to support JWT assertions. For details about creating JWT JSON files, see JWT Assertions Outbound Use in Using the REST Adapter with Oracle Integration 3.

Configure a Connection

  1. The REST Adapter invoke connection is configured with the OAuth using JWT User Assertion security policy. The JWT private key alias specified is the same as the signing key uploaded on the Certificates page in Oracle Integration. See Prerequisites.


    Oracle Integration connection configuration for AUTOMATION_JWT_IDCS_USER_ASSERTION, using a REST API base URL and OAuth using JWT User Assertion security policy. JWT header and payload JSON files are attached, with a JWT private key alias named automation_idcs_key.

  2. The JWT header and payload files created in Prerequisites are uploaded. The JWT payload file contains the sub property, which contains the user identity to propagate from the MCP gateway to the MCP server to the MCP tool invocations (the underlying integrations) to the endpoint system.
    {
      "iss": "a24ga932184c4e81aade747d764b2f02",
      "sub": "mike.smith@example.com",
      "aud": "https://identity.oraclecloud.com/",
      "nbf": 1734994451,
      "exp": 1744998451,
      "iat": 1739994481,
      "jti": "2d29e3b4-982a-71ea-94a2-3785e926dy83"
    }

Map the User Identity

  1. The map action between the trigger and invoke connections defines the subject to propagate.


    The integration consists of a trigger, map action, invoke, and map action.

  2. The source (trigger) Subject element is mapped to the target (invoke) Subject element. This mapping indicates you want to use identity propagation to send the subject to the endpoint system. Oracle Integration generates the downstream access token and invokes the endpoint system with the originating user. Without this mapping, the endpoint system cannot receive the originating user.


    Oracle Integration mapper showing the “Map to getIntegrations” flow, with the required Subject security property mapped directly from the REST trigger request source to the Subject element of the getIntegrations REST request target.

Register the Integrations as MCP Tools

  1. The two integrations are registered as MCP tools for AI agents. See Register the Integration as an Agentic AI Tool.


The Design tab is selected. The AI Agents title is shown. There are no agents created. There are two tools created and configured.

Configure the MCP Server

  1. The MCP server (for this example, named Factory API MCP Server) is selected to be managed by the MCP gateway.


    Oracle Integration MCPGW Test_MS Design page shows the created MCP gateways and MCP servers. The Factory API MCP Server is highlighted and marked as Configured.

  2. Factory API MCP Server is configured as follows:
    The two integrations registered as tools are discovered and displayed on the right side of the page when the connection is tested and saved.
    • JWT_UpdateSecurityPolicyOfAConnection
    • GET_INTEGR_USING_IDENTI_PROPAGATION


    The configured Factory API MCP Server is shown. Properties fields are shown for MCP Endpoint, Issuer, Subject, Audience, and Signing Key ID. In the Security section, the JWT User Assertion for OAuth security policy is selected. Fields are shown below this for Access token URI, JWT Private Key Alias, and Scope. The sidebar shows 100% configuration progress, a successful connection test, and two discovered tools.

    The MCP server properties are configured as follows:

    Element Description
    MCP Endpoint The MCP server endpoint to which to connect.
    Optional properties The claims used to generate the token:
    • Issuer
    • The client ID.
    • Subject
    • The user (for this example, edward.murray@example.com). Note that the user name is different than the user name specified for the subject parameter in the JWT payload file uploaded during REST Adapter invoke connection configuration.
    • Audience
    • Is https://identity.oraclecloud.com.
    • Signing Key ID
    • The signing key (for this example, oicidcs).
    Security policy JWT User Assertion for OAuth is selected for user identity propagation.
    Access token URI The access token URI to use.
    JWT Private Key Alias The JWT private key alias to use (automation_idcs_key). This is the same name specified:
    • When configuring the REST Adapter invoke connection.
    • When uploading the signing key on the Certificates page in Oracle Integration. See Prerequisites.
    Scope The scope of the service instance.

Define the MCP Server and Policies for the MCP Gateway

  1. The MCP gateway is created and configured to manage the MCP server (Factory API MCP Server) described in Configure the MCP Server. A filter is defined to expose both agent AI tool-registered integrations that were discovered.


    Screenshot of the configured “ainagar-test-identity-propagation” MCP gateway. Factory API MCP Server is selected; AWS_KB, Find A Domain, and Echo MCP are unchecked. Under request policies, “Tools Filter For Factory API MCP Server” is enabled, while the second tool filter is unchecked.

Run the MCP Gateway

  1. The MCP gateway is run (for this example, from Postman).
    • The user calls the MCP gateway with their OAuth token. You obtain this token by creating or using an existing confidential application using the OAuth Authorization Code grant type in the Oracle Cloud Console. This token enables the user running the MCP gateway in Postman to have their identity propagated across the MCP gateway, MCP server, and agent AI tool-registered integrations to the endpoint system.
    • When you connect to the gateway, the caller is validated and routes the tool call to the selected MCP server.


    Screenshot of the Configure New Token form with the token name and grant type of Authorization code. Below this are the callback URL, and Auth URL values.

  2. After a token is issued, Run is clicked to connect to the MCP gateway. Note that both integrations registered as tools are displayed.


    Screenshot of an MCP API client showing tools to update a connection’s security policy and retrieve OIC integrations. The JSON request calls the security policy update tool with securityPolicy set to OCI_SERVICE_INVOCATION and connectionId set to UPDATE. The endpoint URL and integration instance are also shown.

  3. Once gateway connectivity is established, you call the MCP server. For this example, the connection is updated to specify a different security policy (OCI Service Invocation) in the specified service instance. The JWT_UpdateSecurityPolicyOfAConnection tool, which calls the Developer API for Oracle Integration 3 to update the security policy of a specific connection in a service instance, is invoked.


    The Tools tab is selected in Postman. The securityPolicy field is set to OCI_SERVICE_INVOCATION, connectionId is set to UPDATE, and integrationInstance is set to the instance name.

  4. Postman returns the response details. The response indicates that the JWT_UpdateSecurityPolicyOfAConnection tool is successfully called.


    The Response tab shows that the tools were called and have connected.

    The response also shows that the user who ran the MCP gateway (for this example, kevin.hoffman@example.com) is propagated through the MCP gateway, MCP server, and agent AI tool-registered integrations to the end system even though two other users were specified during design time. The end user’s identity is determined at runtime by whoever is using the agent, not by users configured at design time.

    {
      "name": "UPDATE",
      "status": "CONFIGURED",
      "securityPolicy": "OCI_SERVICE_INVOCATION",
      "created": "2026-07-30T23:53:35.245+0000",
      "createdBy": "\"",
      "lastUpdatedBy": "kevin.hoffman@example.com"
    }