Skip to main content

Manage connectors

A connector is an MCP server available through the Connector Gateway. After registering a connector, configure its authentication and grant access to it through its connector policy.

The connector list​

The Connectors screen lists every registered connector with its endpoint, transport, state, the number of groups that have access, and when it was created.

Where connectors come from​

Select Add connector and choose how to register the connector:

  • Import from registry adds remote servers that your curated MCP registry publishes.
  • Discover in Kubernetes scans your cluster for running MCP servers and lets you choose which ones to add.
  • Configure manually registers a server by name, endpoint, and transport.

Add MCP servers from your cluster​

Discovery lists every MCPServer resource in your cluster, across all namespaces, as a candidate. Nothing is registered until you select candidates and choose Add to catalog.

Each candidate shows its namespace, transport, and endpoint. If an existing connector already uses a candidate's endpoint, the candidate shows Already added as and the connector's name. A candidate that belongs to an MCP server group shows that group, because a vMCP might already aggregate it and adding it separately would expose its tools twice. If discovery can't determine a candidate's transport, choose one before adding it.

Each server you add becomes a Draft connector with no backend authentication and a description naming the namespace it came from. Open the connector to review its configuration, then save it to publish the connector.

Draft, available, and failure​

Draft connectors are registered but inactive. Activating a connector triggers an endpoint check. A valid MCP endpoint becomes Available; an invalid or unreachable endpoint enters Failure.

Connector settings​

A connector's Configuration tab holds its name, endpoint, transport, and authentication. See Configure connector authentication for the authentication types.

Transport​

The Connector Gateway serves connectors that use the streamable-http or sse transport. SSE is a deprecated MCP transport, so choose Streamable HTTP unless the backend supports only SSE. If a connector's stored transport isn't one of these, the gateway withholds the connector and the console asks you to choose a transport before you can save.

Private network endpoints​

By default, a connector endpoint must use HTTPS (plain HTTP is allowed only for localhost), and the gateway refuses to connect to an address in a private, loopback, or link-local range. In-cluster endpoints resolve to private addresses, so a connector that points at a Kubernetes Service needs Allow private IPs turned on (allow_private_ips in the API). The setting also permits plain HTTP. The gateway never connects to link-local addresses such as the cloud metadata endpoint, even with this setting on.

Discovery turns on Allow private IPs for a candidate whose endpoint is a Service in the candidate's own namespace. For a connector you add manually or import, turn it on yourself when the endpoint is in-cluster.

Access and authentication​

Each connector's connector policy decides who can reach it, either through directory group grants on the Access tab or through a Cedar policy document. The connector's authentication type decides the credential the gateway sends to the backend, including per-user OAuth through an identity provider.

Next steps​