Manage connectors
A connector is an MCP server available through the Connector Gateway. After registering a connector, configure its authentication and grant access to it through its connector policy.
The connector list
The Connectors screen lists every registered connector with its endpoint, transport, state, the number of groups that have access, and when it was created.
Where connectors come from
Select Add connector and choose how to register the connector:
- Import from registry adds remote servers that your curated MCP registry publishes.
- Discover in Kubernetes scans your cluster for running MCP servers and lets you choose which ones to add.
- Configure manually registers a server by name, endpoint, and transport.
Add MCP servers from your cluster
Discovery lists every MCPServer resource in your cluster, across all
namespaces, as a candidate. Nothing is registered until you select candidates
and choose Add to catalog.
Each candidate shows its namespace, transport, and endpoint. If an existing connector already uses a candidate's endpoint, the candidate shows Already added as and the connector's name. A candidate that belongs to an MCP server group shows that group, because a vMCP might already aggregate it and adding it separately would expose its tools twice. If discovery can't determine a candidate's transport, choose one before adding it.
Each server you add becomes a Draft connector with no backend authentication and a description naming the namespace it came from. Open the connector to review its configuration, then save it to publish the connector.
Draft, available, and failure
Draft connectors are registered but inactive. Activating a connector triggers an endpoint check. A valid MCP endpoint becomes Available; an invalid or unreachable endpoint enters Failure.
Connector settings
A connector's Configuration tab holds its name, endpoint, transport, and authentication. See Configure connector authentication for the authentication types.
Transport
The Connector Gateway serves connectors that use the streamable-http or sse
transport. SSE is a deprecated MCP transport, so choose Streamable HTTP
unless the backend supports only SSE. If a connector's stored transport isn't
one of these, the gateway withholds the connector and the console asks you to
choose a transport before you can save.
Private network endpoints
By default, a connector endpoint must use HTTPS (plain HTTP is allowed only for
localhost), and the gateway refuses to connect to an address in a private,
loopback, or link-local range. In-cluster endpoints resolve to private
addresses, so a connector that points at a Kubernetes Service needs Allow
private IPs turned on (allow_private_ips in the API). The setting also
permits plain HTTP. The gateway never connects to link-local addresses such as
the cloud metadata endpoint, even with this setting on.
Discovery turns on Allow private IPs for a candidate whose endpoint is a Service in the candidate's own namespace. For a connector you add manually or import, turn it on yourself when the endpoint is in-cluster.
Access and authentication
Each connector's connector policy decides who can reach it, either through directory group grants on the Access tab or through a Cedar policy document. The connector's authentication type decides the credential the gateway sends to the backend, including per-user OAuth through an identity provider.
Next steps
- Configure connector authentication to set the credential the gateway sends to each backend.
- Manage connector policies to grant access to the connector.
- Configure the Connector Gateway for the install-time settings behind this screen.