Features
1 min read
Capabilities
Capability | What it delivers | Status |
|---|---|---|
Relay and gateway | One MCP endpoint per virtual server routes traffic to approved downstream systems. | Available |
Virtual servers | Curated, role-based MCP endpoints with full draft, publish, and unpublish lifecycle. | Available |
Tool curation | Admins choose exactly which tools are exposed, with clear namespacing across origins. | Available |
Tools, resources, and prompts | The hub aggregates downstream tools, MCP resources, and prompts behind one endpoint. | Available |
Standards-based OAuth | PKCE, dynamic client registration, refresh, and discovery work with any MCP client. | Available |
Per-user downstream OAuth | Each user authenticates to downstream systems individually; credentials stay in the hub. | Available |
Tool elicitation | Tools that need a human in the loop can request confirmation through any MCP client. | Available |
Tool-call audit trail | Tool-call activity is recorded for administrative review. | Available |
Delegated MCP server administration | Tenant MCP admins can assign specific users to manage individual origin MCP servers without granting tenant-wide connector admin access. | Available |
Space restrictions for MCP servers | Admins can limit an origin MCP server to selected Spaces/Assistants. | Available |
DLP and anonymization | Inspect and clean sensitive data before it reaches downstream systems. | Roadmap |
Unique tools as MCP origins | Expose Unique capabilities such as search, web search, SWOT, and sub-agents through virtual servers. | Roadmap |
MCP UI passthrough | Forward rich cards and interactive components from downstream servers to capable clients. | Roadmap |
Feature Groups
Connectivity | Identity and credentials | Governance |
|---|---|---|
One MCP endpoint per virtual server, multi-origin routing, namespaced tools, and resource and prompt passthrough. | Standards-based OAuth, per-user downstream authentication, and centralized credential storage. | Curated tool sets, publish and unpublish lifecycle, tool-call audit trail, feature-flagged delegated connector administration, and selected-space restrictions. |