Dynamic Gateway
Give every user one personalized MCP Gateway shaped by organization defaults, assigned toolkits, and their own connections.
Dynamic Gateway gives every user one primary MCP endpoint for the apps and tools available to them. Admins set the organization-wide boundaries and can distribute task-specific toolkits, while users connect their own accounts and manage their personal choices through MCP Self-Service.
Unlike a Gateway that someone creates for a particular project or client, a user's Dynamic Gateway is already available. Its contents adjust as approved apps, toolkit assignments, user preferences, and connection status change.
Dynamic Gateway always uses Radar. Users and admins do not need to turn Radar on for it.
What shapes a Dynamic Gateway
Each user's Dynamic Gateway can contain:
- Apps marked Featured in Server Management. These start on by default, but users can switch them off.
- Toolkits an admin assigns directly to the user, to one of their groups, or to the whole tenant.
- Apps and personal toolkits the user enables in MCP Self-Service.
The result is one endpoint that reflects both organization policy and the user's own working setup.
Admin and user responsibilities
| Responsibility | Admin | User |
|---|---|---|
| Approve which apps the organization can use | Yes | No |
| Choose Featured apps that start on by default | Yes | No |
| Create and maintain assigned toolkits | Yes | No |
| Assign toolkits to users, groups, or the tenant | Yes | No |
| Connect a personal account to an app | No | Yes |
| Create and edit personal toolkits | No | Yes |
An assigned toolkit appears in the same Toolkits section as a user's personal toolkits. The recipient can use it, but cannot rename it, switch it off, add or remove apps, or change its selected tools. Only an admin can change an assigned toolkit.
Featured apps and assigned toolkits
Featured apps and assigned toolkits solve different problems.
| Control | Best for | What the user receives |
|---|---|---|
| Featured app | Making a broadly useful app easy to start using | The app starts on in the user's Dynamic Gateway, but the user can switch it off |
| Assigned toolkit | Providing a maintained set of apps and tools for a role or task | A complete, admin-managed toolkit that the recipient cannot change |
For example, feature a company-wide search app that most employees may want. Assign a Sales Research toolkit to the sales group when those users need a specific combination of approved research and CRM tools.
Prepare apps for Dynamic Gateway
Only apps available to your organization can be used in a Dynamic Gateway or assigned toolkit.
In Server Management, approve each app users may access.
Mark broadly useful apps as Featured when they should start on in users' Dynamic Gateways.
Review how each app authenticates. If an app requires a personal sign-in, every recipient must connect their own account before its tools can run.
Assigning a toolkit does not sign users in to its apps. When an app requires a personal connection, the toolkit can appear before the user has connected it. MCP Self-Service tells the user which app needs attention.
Assign toolkits
Create a toolkit when you want to maintain a consistent set of apps and tools for other people.
Give the toolkit a name that describes the job it supports, then add its approved apps and choose the tools recipients should receive.
Assign the toolkit to individual users, one or more user groups, or the whole tenant.
Confirm that the selected scope includes everyone who needs the toolkit and no one who does not.
The toolkit appears in the Dynamic Gateway of every recipient and is shown as an admin-managed toolkit in MCP Self-Service.
Choose an assignment scope
| Scope | Use it when |
|---|---|
| Individual users | A small number of named people need the toolkit |
| User groups | Everyone in a team, department, or job function should receive the same toolkit |
| Whole tenant | Every user in the organization should receive the toolkit |
Prefer group assignments when access follows a job function. This keeps the toolkit aligned with group membership without maintaining a separate list of users.
Change or remove an assignment
Admins remain the only people who can change assigned toolkits.
- Editing the apps or tools in a toolkit updates what its recipients receive.
- Adding an assignment makes the toolkit appear for the newly included users.
- Removing an assignment removes the toolkit from users who no longer qualify for it.
- Removing an assignment does not delete a user's personal credentials or personal toolkits.
Monitor usage
Use MCP Monitoring to review calls, errors, and policy denials across your organization's MCP Gateways. Users can review their own recent Dynamic Gateway activity in MCP Self-Service.
