· David

SnapLogic's May release: pipelines as MCP tools, with the user's identity along

SnapLogic's May 2026 release made its MCP Server, AI Gateway and trusted agent identity generally available. Why identity propagation matters for agents.

Les på norsk

Product releases are usually lists of small improvements, and SnapLogic’s May 2026 release has plenty of those. But three features in it, all generally available, show how an iPaaS turns into a platform for agents: pipelines exposed as MCP tools, an AI gateway, and identity that follows the user all the way through.

What SnapLogic released

The agent-related features are:

  • MCP Server. Existing pipelines can be offered as tools that AI agents call through the Model Context Protocol. Access is controlled in SnapLogic’s Policy Manager, with authentication, authorisation and traffic shaping.
  • OAuth 2.0 and trusted agent identity. Support for client credentials and JWT validation, with token propagation, so the end user’s identity follows the request through the integration layer.
  • AI Gateway. One place for authentication, authorisation and throttling of AI traffic, with its own dashboard for MCP observability.
  • Automatic tagging. Pipelines are tagged as “Agent” or “MCP Server” based on what they contain, which makes them easier to find.
  • Audit logging for SnapGPT. All interactions with SnapLogic’s AI assistant are logged and can be retrieved through the public API for up to 45 days.

The release also includes a cache service that SnapLogic says starts pipelines up to 30 times faster, support for JRE 17, and new Snaps, among them an EDIFACT parser and formatter.

Why it matters

The most important feature is the least visible one: that the end user’s identity follows the request. When an agent calls an integration, the question is whose rights apply. If the integration runs with a broad service account, the agent can in practice see and change more than the user who asked it. With token propagation, the target system can apply the user’s own rights.

This is one of the problems that make many companies hesitate to let agents into business systems. Solving it in the integration layer, rather than in each agent, is a strong argument for letting agent traffic pass through the iPaaS.

How it compares

Exposing integrations as MCP tools and adding an AI gateway is now standard among the large iPaaS vendors. Identity propagation is less common, and is worth checking in every evaluation. SnapLogic places the MCP server under the same Policy Manager as its APIs, which means the same rules and the same team can manage both.

What to ask

  1. Whose rights apply? Ask whether the end user’s identity reaches the target system, or whether the integration runs with a shared service account.
  2. Which pipelines should be tools? Decide which pipelines agents should be allowed to call, and review them before they are exposed.
  3. How long are logs kept? Check whether log retention for agent and MCP traffic meets your requirements for audit.

Sources

This post was written with AI assistance and reviewed by the editor before publishing.

← All posts