ComponentsMCP serversAdmin Controls

Dynamic Gateway

Give every user one personalized MCP Gateway shaped by organization defaults, assigned toolkits, and their own connections.

Dynamic Gateway gives every user one primary MCP endpoint for the apps and tools available to them. Admins set the organization-wide boundaries and can distribute task-specific toolkits, while users connect their own accounts and manage their personal choices through MCP Self-Service.

Unlike a Gateway that someone creates for a particular project or client, a user's Dynamic Gateway is already available. Its contents adjust as approved apps, toolkit assignments, user preferences, and connection status change.

Dynamic Gateway always uses Radar. Users and admins do not need to turn Radar on for it.

Diagram of one Dynamic Gateway serving three users from a single URL: an admin assigns toolkits to groups and users, each user selects the toolkits they want, and the gateway returns each user's own tool list and executes their calls against the connected apps

View the full diagram ↗

What shapes a Dynamic Gateway

Each user's Dynamic Gateway can contain:

  • Apps marked Featured in Server Management. These start on by default, but users can switch them off.
  • Toolkits an admin assigns directly to the user, to one of their groups, or to the whole tenant.
  • Apps and personal toolkits the user enables in MCP Self-Service.

The result is one endpoint that reflects both organization policy and the user's own working setup.

Admin and user responsibilities

ResponsibilityAdminUser
Approve which apps the organization can useYesNo
Choose Featured apps that start on by defaultYesNo
Create and maintain assigned toolkitsYesNo
Assign toolkits to users, groups, or the tenantYesNo
Connect a personal account to an appNoYes
Create and edit personal toolkitsNoYes

An assigned toolkit appears in the same Toolkits section as a user's personal toolkits. The recipient can use it, but cannot rename it, switch it off, add or remove apps, or change its selected tools. Only an admin can change an assigned toolkit.

Featured apps and assigned toolkits solve different problems.

ControlBest forWhat the user receives
Featured appMaking a broadly useful app easy to start usingThe app starts on in the user's Dynamic Gateway, but the user can switch it off
Assigned toolkitProviding a maintained set of apps and tools for a role or taskA complete, admin-managed toolkit that the recipient cannot change

For example, feature a company-wide search app that most employees may want. Assign a Sales Research toolkit to the sales group when those users need a specific combination of approved research and CRM tools.

Prepare apps for Dynamic Gateway

Only apps available to your organization can be used in a Dynamic Gateway or assigned toolkit.

In Server Management, approve each app users may access.

Mark broadly useful apps as Featured when they should start on in users' Dynamic Gateways.

Review how each app authenticates. If an app requires a personal sign-in, every recipient must connect their own account before its tools can run.

Assigning a toolkit does not sign users in to its apps. When an app requires a personal connection, the toolkit can appear before the user has connected it. MCP Self-Service tells the user which app needs attention.

Assign toolkits

Create a toolkit when you want to maintain a consistent set of apps and tools for other people.

Give the toolkit a name that describes the job it supports, then add its approved apps and choose the tools recipients should receive.

Assign the toolkit to individual users, one or more user groups, or the whole tenant.

Confirm that the selected scope includes everyone who needs the toolkit and no one who does not.

The toolkit appears in the Dynamic Gateway of every recipient and is shown as an admin-managed toolkit in MCP Self-Service.

Choose an assignment scope

ScopeUse it when
Individual usersA small number of named people need the toolkit
User groupsEveryone in a team, department, or job function should receive the same toolkit
Whole tenantEvery user in the organization should receive the toolkit

Prefer group assignments when access follows a job function. This keeps the toolkit aligned with group membership without maintaining a separate list of users.

Change or remove an assignment

Admins remain the only people who can change assigned toolkits.

  • Editing the apps or tools in a toolkit updates what its recipients receive.
  • Adding an assignment makes the toolkit appear for the newly included users.
  • Removing an assignment removes the toolkit from users who no longer qualify for it.
  • Removing an assignment does not delete a user's personal credentials or personal toolkits.

Monitor usage

Use MCP Monitoring to review calls, errors, and policy denials across your organization's MCP Gateways. Users can review their own recent Dynamic Gateway activity in MCP Self-Service.

Troubleshooting

Was this page helpful?

On this page