Loading…
April 2-3, 2026
New York, NY
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for MCP Dev Summit North America to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration..

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Venue: Empire Complex (7th Floor) clear filter
arrow_back View All Dates
Thursday, April 2
 

11:50am EDT

Securing MCP at Scale: From Principles To Production - Peter Smulovics, Morgan Stanley
Thursday April 2, 2026 11:50am - 12:15pm EDT
As MCP adoption accelerates across platforms, the risks of giving LLMs tool access are growing quickly. This session explores the real threat surface of MCP systems: prompt injection, tool poisoning, unsafe permissions, supply-chain “rug pulls,” cross-tool escalation, and data-exfiltration risks that arise when agents can call arbitrary tools. Building on Microsoft's recent work hardening MCP on Windows, we outline a practical reference architecture for secure deployments: signed and verified tool manifests, unique server identities, scoped capabilities, sandboxed execution, authenticated connections, governance via registries, audit logging, and runtime anomaly detection. Attendees will leave with a blueprint for running MCP in production: what to lock down, how to operate it safely, and how enterprises can integrate MCP into existing security, IAM, and compliance frameworks. This talk equips developers, architects, and security teams to build safer agentic systems and contribute to a more secure MCP ecosystem.
Speakers
avatar for Peter Smulovics

Peter Smulovics

Distinguished Engineer, Morgan Stanley
Peter Smulovics is a Distinguished Engineer at Morgan Stanley with 15+ years at the firm and 30+ in the industry. A 2× Microsoft MVP and co-creator of C#, he serves as Vice Chair of FINOS (Linux Foundation) Technical Oversight Committee and leads Open Source Readiness. He focuses... Read More →
Thursday April 2, 2026 11:50am - 12:15pm EDT
Empire Complex (7th Floor)
  Security and Operations

12:20pm EDT

When MCP Becomes a Product - Gautam Baghel, HashiCorp & Roy Derks, IBM
Thursday April 2, 2026 12:20pm - 12:45pm EDT
MCP servers often begin as simple side projects. You build a quick integration, get a basic connection working, and show a demo. But as users begin to rely on your tool, the stakes change. In this talk, we share the lessons learned from taking multiple of MCP servers from initial Proofs of Concept to robust production standards, supporting tens of thousands of developers across open-source and enterprise environments. These are the real-world realities of treating your MCP server as a shipping product.
Speakers
avatar for Roy Derks

Roy Derks

Developer Experience, IBM
Roy Derks is a lifelong software developer, author and public speaker from the Netherlands. Currently chasing his dreams in Silicon Valley, California. Roy's mission is to make the world a better place through technology by inspiring developers all over the world, more specifically... Read More →
avatar for Gautam Baghel

Gautam Baghel

Sr. Product Manager, Gen AI, HashiCorp, an IBM company
Gautam is a passionate technologist who thrives on solving DevOps puzzles and building meaningful solutions. He's all about automating stuff, streamlining workflows, and building scalable systems. Through his talks, Gautam shares practical insights and inspires others to dive into... Read More →
Thursday April 2, 2026 12:20pm - 12:45pm EDT
Empire Complex (7th Floor)

12:50pm EDT

Golem To Murderbot: Challenges With Agentic Security Delegation Via MCP - Michael Schwartz, Gluu
Thursday April 2, 2026 12:50pm - 1:15pm EDT
To implement "Zero Trust", authorization must be enforced consistently across every layer: inside the agent, in the cloud (like MCP gateways and services), and down to the database. Each layer needs its own dynamic authorization decision engine, yet those decisions must remain aligned and explainable.

As AI agents become first-class actors in enterprise systems, traditional security models start to strain. This session examines how agentic workflows challenge today’s delegation mechanisms, especially when agents act autonomously, chain operations, or cross trust boundaries. We’ll explore where OAuth works well and where it falls short.

The session argues for centralized policy management using Cedar, decoupled from application code to prevent policy drift. It will introduce emerging governance models like GovOps, which treat policies, schemas, and authorization logic as managed assets with lifecycle controls and automated compliance. Attendees will leave with a practical ideas for secure agent delegation and governing agentic systems at scale.

The discussion frame is two narratives: a 15th century myth and a 2025 Apple TV mini-series based Martha Wells' books.
Speakers
avatar for Michael Schwartz

Michael Schwartz

Founder / CEO, Gluu
Mike is the founder of cybersecurity software vendor Gluu, BD of the Linux Foundation Janssen Project, and twice a week hosts the livestream Identerati Office Hours. He is also author of "Securing the Perimeter" (Apress 2018) about open source digital identity. His podcast "Open Source... Read More →
Thursday April 2, 2026 12:50pm - 1:15pm EDT
Empire Complex (7th Floor)
  Security and Operations

2:35pm EDT

From Scopes To Intent: Reimagining Authorization for Autonomous Agents - Andres Aguiar & Abhishek Hingnikar, Okta
Thursday April 2, 2026 2:35pm - 3:00pm EDT
The Model Context Protocol (MCP) has standardized how we connect models to data, but the security layer remains a work in progress. Currently, MCP implements authorization via standard OAuth scopes.

While this works for handling coarse-grained tool access, it presents challenges for finer grained permissions.

To solve this, we must move toward intent-based authorization—a model where agents are authorized to perform actions based on the specific context of a task, rather than a pre-approved list of capabilities.

This presentation will dissect the consequences of the current OAuth model on agent design and present ideas of how to address them. We will discuss how to implement dynamic authorization that allows agents to be helpful without being intrusive, ensuring that security scales alongside intelligence.
Speakers
AH

Abhishek Hingnikar

Product Architect, Okta
avatar for Andres Aguiar

Andres Aguiar

Director of Product @ Okta, Okta
Solving Authorization with openfga.dev | fga.dev
Thursday April 2, 2026 2:35pm - 3:00pm EDT
Empire Complex (7th Floor)
  Security and Operations

3:05pm EDT

Deploying MCP at Scale Without Skipping Compliance - Becky Brooks, MCP Manager by Usercentrics
Thursday April 2, 2026 3:05pm - 3:30pm EDT
With EU AI Act enforcement beginning this year, teams deploying MCP need to understand what regulators will actually look for in production systems.

This talk is a practical guide for builders and IT teams deploying MCP at scale without dodging compliance. We’ll break down the concrete requirements emerging from regulation, including audit logs, traceability, access controls, and oversight mechanisms, and show how they map directly to MCP-based architectures.

We’ll cover how compliance applies across the systems MCP touches, from internal tools and data sources to the emerging MCP Apps ecosystem, where consumer-facing workflows introduce new expectations around transparency, consent, and accountability as AI increasingly mediates how brands and consumers interact.

Attendees will leave with a clear picture of what it takes to deploy MCP that works in production and holds up under regulatory scrutiny.
Speakers
avatar for Becky Brooks

Becky Brooks

Staff Product Marketing Manager, MCP Manager by Usercentrics
Becky Brooks is a Staff Product Marketing Manager at MCP Manager by Usercentrics, where she helps teams safely and confidently deploy MCP in real-world AI systems. She focuses on making MCP accessible and trustworthy so teams can use AI to move faster without sacrificing safety or... Read More →
Thursday April 2, 2026 3:05pm - 3:30pm EDT
Empire Complex (7th Floor)
  Security and Operations
  • Audience Experience Level Any

3:35pm EDT

Shadow MCP: Finding the MCPs Nobody Approved - Aidan Sochowski & Alexander Frazer, Runlayer
Thursday April 2, 2026 3:35pm - 4:00pm EDT
Shadow IT is back - but this time it's AI-powered. Employees are configuring MCP servers directly in Cursor, Claude Desktop, and VS Code, creating a blind spot that traditional security tools miss. These shadow MCPs operate outside centralized control, enabling data exfiltration, supply chain attacks, and compliance violations.

This talk exposes the shadow MCP problem and presents a comprehensive detection and response framework:

- Why shadow MCPs are uniquely dangerous (AI amplifies access, automates actions, no audit trail)
- Discovery techniques: IDE config scanning, MDM integration, network detection patterns
- Classification: distinguishing managed vs shadow servers across device fleets
- Response playbooks: triage, investigation, remediation by risk level

I'll share real vulnerability examples from official MCPs (GitHub, Asana, Supabase, Postmark) and demonstrate automated detection through IDE hooks (Cursor, Claude Code) and MDM platforms (SimpleMDM, Jamf).

Attendees will leave with practical techniques for gaining visibility into shadow MCP usage and a framework for bringing unauthorized integrations under organizational control.
Speakers
AS

Aidan Sochowski

Senior Product Engineer, Runlayer
Aidan is a founding product engineer at Runlayer. Previously he's worked
at Glean on scalable connector and crawler infrastructure and at YouTube
on recommendations serving infrastructure

... Read More →
avatar for Alexander Frazer

Alexander Frazer

Founding Security Engineer, Runlayer
Alexander Frazer is a Founding Security Engineer at Runlayer, specializing in generative AI and cybersecurity. With 15+ years of experience, he focuses on AI security challenges and MCP implementations. Previously he has led creation and evaluation of AI-driven security triage systems... Read More →
Thursday April 2, 2026 3:35pm - 4:00pm EDT
Empire Complex (7th Floor)
  Security and Operations

4:30pm EDT

If You Can Secure It Here, You Can Secure It Anywhere - Milan Williams & Katrina Liu, Semgrep
Thursday April 2, 2026 4:30pm - 4:55pm EDT
Here's the thing about being a security company: you can't ship a vulnerable MCP server. For us, getting pwned isn’t just embarrassing - it gets us on the front page of Hacker News. Our customers trust us to protect them from nation-state attackers, well-funded adversaries (and the odd teenager attacking for lolz.)

At the same time, the MCP ecosystem is still maturing. Hardening standards for sophisticated attackers don't exist yet. And with high-profile supply chain attacks now targeting agents, attackers are actively exploiting the trust developers place in their toolchains. Last year, a flaw in mcp-remote turned into a remote code execution nightmare, exposing over 400,000 developers. That's the reality we're building in.


When it came to our MCP server, we built it using the same rigor we use to protect the world's largest companies. This talk covers the threat model we designed against, gaps in MCP's current design that required workarounds, and ultimately how we built an MCP server trusted by enterprise customers, and hardened against even the most novel attacks. If we can secure it here, you can secure it anywhere.
Speakers
avatar for Milan Williams

Milan Williams

Senior Product Manager, Semgrep
I build security products. I'm a Senior Product Manager at Semgrep, a high-growth cybersecurity startup. I lead the teams responsible for Semgrep Code (SAST) and Secrets detection products.

I recently graduated from Harvard University with degrees in Computer Science and Physics. In my free time, you can find me geeking about the latest in security / developer tooling, running in San Francisco's Golden Gate Park, or enjoying local theater... Read More →
avatar for Katrina Liu

Katrina Liu

Software Engineer, Semgrep
Katrina is a software engineer at Semgrep. She is on the Semgrep Analysis Foundations Team, the team that owns and maintains the core static analysis functionality of the Semgrep tool. She is currently working on Semgrep's MCP server.
Thursday April 2, 2026 4:30pm - 4:55pm EDT
Empire Complex (7th Floor)
  Security and Operations

5:00pm EDT

Towards Building Safe & Secure Agentic AI - Dawn Song, UC Berkeley; UC Berkeley Center for Responsible Decentralized Intelligence & Matt White, Linux Foundation/PyTorch Foundation
Thursday April 2, 2026 5:00pm - 5:25pm EDT
Recent advancements in agentic AI have unlocked powerful new capabilities, however, they also introduce fundamentally new security risks. In this talk, I present a system-level view of the security landscape of agentic AI, drawing on a comprehensive systematization of attacks and defenses across modern agent architectures.

I show how increasing agent flexibility along different dimensions expands attack surfaces and enables threats such as prompt injection, memory poisoning, unsafe data flows, credential leakage, and unauthorized execution. Using real-world incidents and CVE analyses, I illustrate how agents can be manipulated through external content, compromised tools, or poisoned internal components.

The talk also provides a systematic overview of end-to-end automatic red teaming and risk assessment for agentic AI systems as well as a defense-in-depth framework for building secure agentic systems, spanning runtime guardrails, access control, information-flow tracking, privilege separation, and secure-by-design architectures, helping practitioners assess risk, close security gaps, and deploy agents safely at scale.
Speakers
avatar for Dawn Song

Dawn Song

Professor, Computer Science @ UC Berkeley and Director of Berkeley RDI (Berkeley Center for Responsible Decentralized Intelligence), UC Berkeley; UC Berkeley Center for Responsible Decentralized Intelligence
Dawn Song is a UC Berkeley CS Professor & Berkeley RDI Co-Director. She is the recipient of the MacArthur, Guggenheim, ACM, IEEE, and Sloan Fellowship, Schmidt Sciences AI2050 Senior Fellowship, NSF CAREER Award, MIT Technology Review TR-35 Award, ACM SIGSAC Outstanding Innovation... Read More →
avatar for Matt White

Matt White

Global CTO of AI, Linux Foundation
Matt White is the Executive Director of the PyTorch Foundation and GM of AI at the Linux Foundation. He is also the Director of the Generative AI Commons. Matt has nearly 30 years of experience in applied research and standards in AI and data in telecom, media and gaming industries... Read More →
Thursday April 2, 2026 5:00pm - 5:25pm EDT
Empire Complex (7th Floor)
  Security and Operations
  • Audience Experience Level Any
  • Session Slides Yes

5:30pm EDT

MCP Traffic Handling at Scale: Stateless Design, Proxies, and the Road Ahead - Erica Hughberg, Tetrate & Boteng Yao, Google
Thursday April 2, 2026 5:30pm - 5:55pm EDT
As MCP adoption grows, teams are facing a new set of challenges: session management across fleets, policy enforcement for agents and users, and operating MCP traffic at scale.

We’ll explore how proxies currently handle stateful MCP sessions, how stateless designs dramatically simplify scaling and operations, and how proxies like Envoy can enforce authorization, tool safety, and policy without becoming bottlenecks. The discussion will also look ahead to emerging MCP proposals, including stateless transports, async tasks, and server discovery, and why alignment between protocol evolution and proxy implementations matters for the ecosystem.

Attendees will leave with concrete architectural insights, practical lessons learned, and a clearer picture of where MCP traffic handling is headed and how to build for it now.
Speakers
avatar for Boteng Yao

Boteng Yao

Software Engineer, Google
Boteng is a Senior Envoy Maintainer and Software Engineer at Google, working on Envoy for various products with an emphasis on data plane, reliability, and security.
avatar for Erica Hughberg

Erica Hughberg

Envoy AI Gateway Maintainer, Tetrate
Erica Hughberg is a technical leader, software engineer, and community advocate passionate about helping engineering teams develop scalable, secure, and user-focused application platforms. As a maintainer of Envoy AI Gateway, she concentrates on features that enable organizations... Read More →
Thursday April 2, 2026 5:30pm - 5:55pm EDT
Empire Complex (7th Floor)
  Security and Operations
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Session Slides
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -