
CIMD prevents phishing at registration. Servers verify the client's actual domain — not just what it claims.
RS256-signed JWTs validate at Kong, AWS API GW, or Cloudflare Workers without a live Scalekit call.





Every MCP client that connects — Dynamic, CIMD, or pre-registered. Call frequency per client.
Full chain per auth request: who, what method, consent granted, token issued.
Forward auth events to Datadog, Splunk, or any SIEM. API access on all plans.




CIMD prevents phishing at registration. Servers verify the client's actual domain — not just what it claims.
RS256-signed JWTs validate at Kong, AWS API GW, or Cloudflare Workers without a live Scalekit call.
Token lifetime, scopes, and user consent managed per MCP server — revoke any grant in one click.

