The service itself needs to control what the agent can access.
Relying on an intermediary to provide access controls, and that agents will never access the service directly, seems dangerous and naive.
And it's easy for the service to do that by hosting a remote MCP server.
What? Why? More is more but you're arguing a security proxy is a dangerous and naive pattern?
Agent doesn't have api key to access service directly