Skip to main content

Manage connectors

A connector is an MCP server available through the Connector Gateway. After registering a connector, configure its authentication and grant access to it through its connector policy.

The connector list​

The Connectors screen lists every registered connector with its endpoint, transport, state, the number of groups that have access, and when it was created.

Where connectors come from​

Select Add connector and choose how to register the connector:

  • Import from registry adds remote servers that your curated MCP registry publishes.
  • Discover in Kubernetes scans your cluster for running MCP servers and lets you choose which ones to add.
  • Configure manually registers a server by name, endpoint, and transport.

Add MCP servers from your cluster​

Discovery lists every MCPServer resource in your cluster, across all namespaces, as a candidate. Nothing is registered until you select candidates and choose Add to catalog.

Each candidate shows its namespace, transport, and endpoint. If an existing connector already uses a candidate's endpoint, the candidate shows Already added as and the connector's name. A candidate that belongs to an MCP server group shows that group, because a vMCP might already aggregate it and adding it separately would expose its tools twice. If discovery can't determine a candidate's transport, choose one before adding it.

Each server you add becomes a Draft connector with no backend authentication and a description naming the namespace it came from. Open the connector to review its configuration, then save it to publish the connector.

Draft, available, and failure​

Draft connectors are registered but inactive. Activating a connector triggers an endpoint check. A valid MCP endpoint becomes Available; an invalid or unreachable endpoint enters Failure.

Connector settings​

A connector's Configuration tab holds its name, endpoint, transport, and authentication. See Configure connector authentication for the authentication types.

Transport​

The Connector Gateway serves connectors that use the streamable-http or sse transport. SSE is a deprecated MCP transport, so choose Streamable HTTP unless the backend supports only SSE. If a connector's stored transport isn't one of these, the gateway withholds the connector and the console asks you to choose a transport before you can save.

Private network endpoints​

By default, a connector endpoint must use HTTPS (plain HTTP is allowed only for localhost), and the gateway refuses to connect to an address in a private, loopback, or link-local range. In-cluster endpoints resolve to private addresses, so a connector that points at a Kubernetes Service needs Allow private IPs turned on (allow_private_ips in the API). The setting also permits plain HTTP. The gateway never connects to link-local addresses such as the cloud metadata endpoint, even with this setting on.

Discovery turns on Allow private IPs for a candidate whose endpoint is a Service in the candidate's own namespace. For a connector you add manually or import, turn it on yourself when the endpoint is in-cluster.

API-only fields​

These connector fields are available only through the Enterprise Manager API:

FieldDescription
icon_urlAbsolute HTTP or HTTPS URL of the connector's icon.
repository_urlAbsolute HTTP or HTTPS URL of the connector's source code.
support_urlAbsolute HTTP or HTTPS URL of the connector's support or home page.
versionFree-text version string.
drafttrue withholds the connector from the gateway, and false publishes it.
originWhere the connector came from: manual (the default), kubernetes_cluster, custom_registry, or stacklok_registry. Set on create only.

The connector update route, PUT /v1/gateways/{gateway_id}/connectors/{id}, replaces the whole connector. Send every field you want to keep, including draft.

Tool names that clients see​

The Connector Gateway prefixes every tool with its connector's name and a short hash, so tools from different connectors never collide. A tool's advertised name has this form:

<CONNECTOR_NAME>_<HASH>_<TOOL_NAME>

The connector name has every character outside a-z, A-Z, 0-9, _, and - replaced with _. The hash is eight characters derived from the connector's ID, so it stays the same when other connectors are added or removed. For example, the list_channels tool on a connector named Slack appears as Slack_a3f2b1c9_list_channels. If the full name exceeds 128 characters, the gateway shortens the connector name segment first.

Renaming a connector renames its tools

A tool name includes the connector name, so renaming a connector changes the name of every tool it advertises. MCP clients and agents that saved the old tool names stop finding those tools. The console doesn't warn about this when you rename a connector.

Access and authentication​

Each connector's connector policy decides who can reach it, either through directory group grants on the Access tab or through a Cedar policy document. The connector's authentication type decides the credential the gateway sends to the backend, including per-user OAuth through an identity provider.

Next steps​