Skip to content
Warplock

One request, there and back.

A request is a single warp thread. Each stage lifts it, checks it, and passes it on. Nothing reaches the database that was not lifted at every bar, and the response climbs back through the same bars before the model sees a row.

The route

POST https://<gateway-host>/mcp/<gatewayEndpointPublicId>

The path segment is an opaque Gateway endpoint ID, not a Client or database name. The bearer is an MCP Access Token or an OAuth token linked to one.

The six stages

  1. 01 · Cloud edge

    WAF

    Barracuda CloudGen WAF

    The thread enters at the edge and is inspected before anything answers it. TLS inspection, intrusion detection and prevention, and a source allowlist decide whether it reaches the next bar at all.

    • TLS inspection of inbound traffic
    • Intrusion detection (IDS) on every session
    • Intrusion prevention (IPS) that drops matched traffic before it is routed
    • Source allowlists rendered from Microsoft service tags and manual CIDRs
    • Firewall-ready CIDR artifacts generated from the Gateway's Source Allowlist Policy

    Passes on Traffic from an allowed source network.

  2. 02 · Cloud edge

    Load balancer

    High-availability load balancer

    Public hostname, DNS and TLS. Many MCP Gateways share port 443 through distinct hostnames, and traffic is steered to a healthy Gateway service.

    • TLS termination and certificate lifecycle
    • Per-Gateway public HTTPS hostname from ingress metadata
    • Routing to the upstream Gateway service and port
    • Health-aware steering across Gateway services

    Passes on An HTTPS request bound for one opaque /mcp/:id route.

  3. 03 · Warplock · Sovereign cloud

    MCP Gateway

    Gateway service

    The bar that knows who is asking. The MCP Access Token is validated, scoped and never forwarded upstream.

    • Token hash lookup, expiry and revocation on every request
    • tools/list and resources filtered to the token's allowed Exposed Entities
    • Disallowed tools/call rejected before proxying (HTTP 403)
    • Source Allowlist Policy enforced in-process after auth and before the body is read, when the policy is in enforcing mode
    • Rate limits at Client, DAB Instance, Environment, token and entity scope
    • Metadata-only Query Audit written for every authenticated request

    Passes on A scoped JSON-RPC call with internal scope headers, no bearer token.

  4. 04 · Warplock · Sovereign cloud

    Policy pipe

    Gateway transforms + promoted policy

    What the model is allowed to see, and how it is described. Part of it runs in the Gateway on every request; part of it is policy Warplock stages and DAB enforces.

    • Column Redaction rules rewrite JSON and event-stream responses in the Gateway
    • TFN Redaction by DAB Instance default or entity override, before anything leaves the Gateway
    • Row Filter Presets, staged in Warplock and enforced by DAB as database policies after promotion
    • Retained payload capture, redaction and digest per Query Audit Payload Policy
    • Gateway-owned MCP Resources carry entity and column descriptions to the model
    • Control-plane schema analysis prefills keys, grain and descriptions so those resources are worth reading

    Passes on A request DAB is allowed to execute; a response the token is allowed to read.

  5. 05 · Warplock · Sovereign cloud

    DAB

    Microsoft Azure Data API builder

    Microsoft certified runtime, secured by Warplock. It executes only the entities Warplock promoted. Generated config, pinned image, no secrets in config.

    • Entity mapping and permission evaluation
    • MCP tool schema generation per Exposed Entity
    • REST and GraphQL endpoints enabled per entity when required
    • Immutable Effective Config Version per DEV, STAGING and PROD

    Passes on A query against the SQL principal the Client provided.

  6. 06 · Backhaul

    Backhaul

    Private Ethernet/Fibre · Tunnel · VPN · SD-WAN · SSH bastion

    The thread leaves the sovereign cloud on a private path agreed with you, never across the open internet to your database.

    • Private Ethernet or fibre where the sovereign cloud and your environment share a facility
    • Site-to-site VPN or SD-WAN into your network
    • Encrypted tunnel or SSH bastion for a single host
    • Fixed egress addresses you can allowlist on your own firewall
    • Only the SQL host and port you nominated are reachable; loopback, link-local and reserved targets fail closed

    Passes on A SQL session to the host and port you nominated.

  7. 07 · Your data

    Database

    Public cloud · Private cloud · IaaS · On-premises

    The strongest boundary is still yours, wherever it already runs. Database permissions, row-level security and procedure behaviour are never replaced, only narrowed on top of.

    • SQL Server, Azure SQL, PostgreSQL, MySQL or Cosmos DB, in your public cloud, private cloud, IaaS or on-premises
    • Authentication and database permissions
    • Row-level security and views
    • Stored procedure behaviour under a Procedure Contract

    Passes on Rows. Then the thread climbs back through every bar it came down.

The way back

The response is not trusted because the request was.

  1. Database → backhaul → DAB

    Rows return over the same private path, under the SQL principal's own permissions. Anything the principal cannot read was never read.

  2. DAB → policy pipe

    Column Redaction and TFN Redaction rewrite JSON and event-stream bodies. The retained payload, if policy retains one, is redacted and digested before it is stored.

  3. Policy pipe → MCP Gateway

    Upstream cookies, redirects, auth challenges and CORS headers are stripped. The Query Audit ID is attached as a response header.

  4. MCP Gateway → client

    The response goes back through the load balancer and WAF as it came, with no-store caching and nothing the token was not allowed to see.

Who owns each bar

Responsibility is written down per stage so that no boundary is assumed. Everything up to the database is part of the Warplock service; the database stays yours.

Cloud edge

  • Barracuda CloudGen WAF: TLS inspection, IDS, IPS, source allowlists
  • High-availability load balancing, DNS, TLS termination and certificate lifecycle
  • Public hostnames per MCP Gateway

Warplock · Sovereign cloud

  • MCP Gateway routing, token enforcement, discovery filtering
  • Policy pipe: redaction, row filters, payload capture, descriptions
  • Draft Change, Promotion and Effective Config Versions
  • DAB runtimes: SQL connectivity, entity mapping, permission evaluation, tool schema
  • Query Audit, retention, rate limits, notifications
  • Hosts, patching, backups of control-plane and runtime state

Backhaul

  • Private Ethernet or fibre, site-to-site VPN, SD-WAN, encrypted tunnel or SSH bastion
  • Fixed egress addresses for your firewall allowlist
  • Reachability limited to the nominated SQL host and port

Your data

  • The database itself, in public cloud, private cloud, IaaS or on-premises
  • Authentication, database permissions and grants
  • Row-level security and views
  • Stored procedure behaviour
  • Backup and restore of the source database

What the client sends

Standard MCP over Streamable HTTP. Warplock adds a Query Audit ID response header and its own resource helper tools; the governance is in what comes back.

curl -i \
  -H "Authorization: Bearer $MCP_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":"1","method":"tools/list"}' \
  https://<gateway-host>/mcp/<gatewayEndpointPublicId>

A restricted token receives only its allowed tools in the list. A disallowed tools/call returns 403 and still writes a metadata-only Query Audit row.

Walk the thread with a real database.

Your partner will map these 7 bars against your own network and SQL estate.

Talk to a partner in your area