API keys don't scale beyond engineering
DNSFilter saw the same opportunity every IT team sees. People in HR, sales, marketing, and finance wanted to put AI to work on the systems they touched every day: the CRM, the staff database, internal records. Engineers could already do it with API keys and a script. Everyone else was stuck.
An API key gives whoever holds it root over the underlying service. There's no per-user scoping, no per-role rate limit, and no good way to disable specific actions. Handing one to a non-engineer is the same as handing over the keys to the kingdom, now with an LLM attached.

“I have people in HR or sales that need access to our CRM. I can't get them the API key, and I shouldn't be able to.”
Mikey Pruitt
Head of AI Labs, DNSFilter
Building scoped permissioning into every system by hand wasn't realistic. DNSFilter needed a layer that did it once and applied it everywhere.
What DNSFilter deployed
DNSFilter put Mint in front of every system that non-engineers needed to touch. Every connector uses per-user OAuth on the underlying service, so when a sales agent calls the CRM, the CRM sees the rep, not a shared service account. People inherit the permissions they already have.
Then the team turned off everything destructive. Updates, deletes, and outbound writes are disabled at the gateway during rollout. Agents can read what they need and create notes or drafts, but nothing irreversible. Those controls open up gradually as the team builds confidence in each use case.
“We're trying to get everyone able to do the things I can do with my cloud account. They can't, because we can't be passing around API keys.”
From there, adoption spread on its own. Mikey connected the team's go-to-market tools through the gateway one at a time, and requests kept coming from people who had never had a way to put AI near those systems before. Even the security team landed in an unusual place: if DNSFilter didn't standardize on Mint, their own next move would be to go find something just like it.
“Each person identifies as themselves and gets their permissions. The destructive behaviors are off while we're still in the learning phase.”
The result reframed who at DNSFilter gets to use AI on real systems. Engineers already had it through API keys and scripts. Now sales, marketing, HR, and finance have it too, through the same systems but with sharper boundaries.
What DNSFilter told us
- SecurityWhy couldn't you just hand out API keys?
- “An API key gives whoever holds it root over the system. There's no per-user scoping, the only rate limit is on the whole key, and you can't disable individual actions even if you wanted to. Handing one to a non-engineer is the same as handing them root with an LLM in the loop. Not a risk we can take.”
- SecurityWhat did you need from a gateway?
- “A scoped boundary in front of every system, with read-only as the default. Specific tools that we could turn on per role, per-user OAuth on the underlying connector so each person inherits their own permissions, and nothing destructive available without an explicit unlock.”
- RolloutHow did you land on Mint?
- “I was on a support call with someone from the MintMCP team. He pasted a documentation URL into Slack, asked an agent to write the connector docs for it, and five minutes later he sent me a link to the new docs already published on their site. That was the day we became a customer.”
- SecurityHow does per-user OAuth work day-to-day?
- “Every connector authenticates as the user, not the agent. When someone in sales asks Claude to do something with the CRM, the CRM sees them and gives them their normal permissions. The agent inherits the user's identity, not a shared service account.”
- SecurityHow do you handle destructive actions?
- “All turned off at the gateway. Updates, deletes, outbound writes: disabled while we're still learning what these agents do in production. Agents can read everything they need and create notes or drafts. We'll open up more as we get comfortable, one action at a time.”
- RolloutWhat's an example of an agent doing real work?
- “We have our CRM and our meeting transcription service connected through the gateway. After a customer call, someone asks Claude for a recap plus the relevant account details, and it pulls both together in under a minute. That kind of cross-tool workflow used to need a custom integration or a person stitching it by hand.”
- ImpactWho's using the agents now?
- “Sales, marketing, HR, finance: every non-engineering team that touches the CRM or our staff systems. They don't need to know what an API or an OAuth flow is. They open Claude and ask for what they need.”
- ImpactHow is this changing how DNSFilter operates?
- “People come to me every day saying 'I use this other tool for X, can I just do it through Claude now?' Usually the answer is yes. Engineers used to be the bottleneck for AI tooling. Now they review the work after the fact instead of gating access to it.”
- ImpactHow did your security team come around?
- “My security guy summed it up: if we didn't land on MintMCP, our next move would be to go find something just like it, so why wouldn't we? Once the team saw they could scope every tool and watch every call, the pushback turned into this being the safe way to do it.”
- ImpactWhat would you tell a peer evaluating an MCP gateway?
- “Look at it as the unlock for non-engineers. The engineers on your team will keep using API keys and CLIs directly, and that's fine. They know what they're doing. Every business user you want to bring along needs a real boundary in front of the systems they touch. An MCP gateway is the cleanest way to put one there.”
Move from API keys for engineers to agents for everyone
See how Mint gives security visibility and controls without slowing engineering down. Read more stories