Skip to main content

Manage connectors

A connector is an MCP server available through the Connector Gateway. Manage connectors in the console under Connectors. After registering a connector, configure its authentication and grant access to it through its connector policy.

Connector sources​

Select Add connector and choose a source:

  • Import from registry adds remote MCP servers that your curated MCP registry publishes.
  • Discover in Kubernetes lists the MCPServer resources running in your cluster. Select the ones you want and choose Add to catalog. Each one becomes a draft connector.
  • Configure manually registers any MCP server by name, endpoint, and transport.

Connector settings​

A connector's Configuration tab holds its name, endpoint, transport, and authentication. See Configure connector authentication for the authentication types.

Draft, available, and failure​

Draft connectors are registered but inactive. Activating a connector triggers an endpoint check. A valid MCP endpoint becomes Available; an invalid or unreachable endpoint enters Failure.

Transport​

The Connector Gateway serves connectors that use the streamable-http or sse transport. SSE is a deprecated MCP transport, so choose Streamable HTTP unless the backend supports only SSE. If a connector's stored transport isn't one of these, the gateway withholds the connector and the console asks you to choose a transport before you can save.

Private network endpoints​

By default, a connector endpoint must use HTTPS (plain HTTP is allowed only for localhost), and the gateway refuses to connect to an address in a private, loopback, or link-local range. In-cluster endpoints resolve to private addresses, so a connector that points at a Kubernetes Service needs Allow private IPs turned on (allow_private_ips in the API). The setting also permits plain HTTP. The gateway never connects to link-local addresses such as the cloud metadata endpoint, even with this setting on.

Discovery turns on Allow private IPs for a candidate whose endpoint is a Service in the candidate's own namespace. For a connector you add manually or import, turn it on yourself when the endpoint is in-cluster.

Access and authentication​

Each connector's connector policy decides who can reach it, either through directory group grants on the Access tab or through a Cedar policy document. The connector's authentication type decides the credential the gateway sends to the backend, including per-user OAuth through an identity provider.

Next steps​