Free course material
Make interoperable tools trustworthy in use.
MCP Security Engineering
Secure Model Context Protocol servers, clients, tools, identities, dependencies, and agent-protocol workflows from first principles.
What this course is about
A practical path from understanding to application.
MCP makes tools, resources, and prompts interoperable; it does not make them trusted. This notebook-first course teaches how trusted applications validate, authorize, execute, verify, and record agent-proposed actions across protocol lifecycles, identity boundaries, delegation, isolation, supply chains, testing, incidents, and enterprise governance.
Covered material
What learners will work through.
- MCP lifecycle, protocol authority, trust boundaries, threat modeling, and safe interfaces
- Server, client, tool, resource, prompt, and transport attack surfaces
- Identity, authorization, delegation, least privilege, and credential handling
- Isolation, dependency and supply-chain security, release evidence, and provenance
- Adversarial testing, composition risk, assurance, incident response, and recovery
- Enterprise MCP governance, operational controls, and production readiness
Who it is for
Meet learners where they are.
Engineers, security practitioners, architects, platform teams, agent developers, and governance owners responsible for MCP servers, clients, tools, integrations, or protocol supply chains.
Adapt this course
Bring the material to your organization.
We can adapt the level, examples, exercises, and pace for executives, non-technical groups, technical teams, or mixed audiences. Sessions combine theory with practical and coding work where it fits, led by educators who meet with your group.
Book a custom training conversationRelated One+i service
AI governance & technical leadership
Connect open learning with the strategy, delivery, and adoption support around it.