# Features

1 min read

## Capabilities

| **Capability** | **What it delivers** | **Status** |
| --- | --- | --- |
| Relay and gateway | One MCP endpoint per virtual server routes traffic to approved downstream systems. | Available |
| Virtual servers | Curated, role-based MCP endpoints with full draft, publish, and unpublish lifecycle. | Available |
| Tool curation | Admins choose exactly which tools are exposed, with clear namespacing across origins. | Available |
| Tools, resources, and prompts | The hub aggregates downstream tools, MCP resources, and prompts behind one endpoint. | Available |
| Standards-based OAuth | PKCE, dynamic client registration, refresh, and discovery work with any MCP client. | Available |
| Per-user downstream OAuth | Each user authenticates to downstream systems individually; credentials stay in the hub. | Available |
| Tool elicitation | Tools that need a human in the loop can request confirmation through any MCP client. | Available |
| Tool-call audit trail | Tool-call activity is recorded for administrative review. | Available |
| Delegated MCP server administration | Tenant MCP admins can assign specific users to manage individual origin MCP servers without granting tenant-wide connector admin access. | Available |
| Space restrictions for MCP servers | Admins can limit an origin MCP server to selected Spaces/Assistants. | Available |
| DLP and anonymization | Inspect and clean sensitive data before it reaches downstream systems. | Roadmap |
| Unique tools as MCP origins | Expose Unique capabilities such as search, web search, SWOT, and sub-agents through virtual servers. | Roadmap |
| MCP UI passthrough | Forward rich cards and interactive components from downstream servers to capable clients. | Roadmap |

## Feature Groups

| **Connectivity** | **Identity and credentials** | **Governance** |
| --- | --- | --- |
| One MCP endpoint per virtual server, multi-origin routing, namespaced tools, and resource and prompt passthrough. | Standards-based OAuth, per-user downstream authentication, and centralized credential storage. | Curated tool sets, publish and unpublish lifecycle, tool-call audit trail, feature-flagged delegated connector administration, and selected-space restrictions.
