| Relay and gateway |
One MCP endpoint per virtual server routes traffic to approved downstream systems. |
Available |
| Virtual servers |
Curated, role-based MCP endpoints with full draft, publish, and unpublish lifecycle. |
Available |
| Tool curation |
Admins choose exactly which tools are exposed, with clear namespacing across origins. |
Available |
| Tools, resources, and prompts |
The hub aggregates downstream tools, MCP resources, and prompts behind one endpoint. |
Available |
| Standards-based OAuth |
PKCE, dynamic client registration, refresh, and discovery work with any MCP client. |
Available |
| Per-user downstream OAuth |
Each user authenticates to downstream systems individually; credentials stay in the hub. |
Available |
| Tool elicitation |
Tools that need a human in the loop can request confirmation through any MCP client. |
Available |
| Tool-call audit trail |
Tool-call activity is recorded for administrative review. |
Available |
| Delegated MCP server administration |
Tenant MCP admins can assign specific users to manage individual origin MCP servers without granting tenant-wide connector admin access. |
Available |
| Space restrictions for MCP servers |
Admins can limit an origin MCP server to selected Spaces/Assistants. |
Available |
| DLP and anonymization |
Inspect and clean sensitive data before it reaches downstream systems. |
Roadmap |
| Unique tools as MCP origins |
Expose Unique capabilities such as search, web search, SWOT, and sub-agents through virtual servers. |
Roadmap |
| MCP UI passthrough |
Forward rich cards and interactive components from downstream servers to capable clients. |
Roadmap |