> ## Documentation Index
> Fetch the complete documentation index at: https://portkey-docs-mintlify-bedrock-guardrails-docs-36443.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Architecture

## System Overview

<Frame>
  <img src="https://mintcdn.com/portkey-docs-mintlify-bedrock-guardrails-docs-36443/Zuam8rvG6vNs05_9/images/product/mcp-gateway/architecture.png?fit=max&auto=format&n=Zuam8rvG6vNs05_9&q=85&s=e9920ef705649a47820050c2a2c3cb66" width="1070" height="884" data-path="images/product/mcp-gateway/architecture.png" />
</Frame>

## Security Architecture

The gateway implements defense-in-depth security:

1. **Client Authentication**: OAuth 2.1 tokens validated on every request
2. **Authorization**: Scope-based access control for MCP operations
3. **Token Isolation**: Client tokens never forwarded to upstream servers
4. **Session Security**: Cryptographically secure session IDs with token-aligned expiration
5. **Transport Security**: TLS encryption for all connections
6. **Audit Logging**: Complete request/response audit trail
