All guides

Register and Approve MCP Tool Servers

Keep a registry of the MCP servers your agents may use, give each server its own tool rules, and put an approval step in front of activation.

10 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02Why register a server
  3. 03Register a server
  4. 04The approval step
  5. 05Give each server its own tool rules
  6. 06Let a policy use the server
  7. 07The server URL must match
  8. 08Enable, disable, and edit
  9. 09Keep it as code
  10. 10If something goes wrong

01

What you'll set up

The registry is your list of MCP servers that agents may use. In about ten minutes you will register a server, give it its own tool rules, route its activation through an approval, and let a policy use it.

  • A registered MCP server with a name and URL
  • Allowed and denied tools for that server
  • An approval step before the server goes live
  • A policy that is allowed to use it

Owners and admins register servers. You need a policy already bound to your agent's traffic.

02

Why register a server

An MCP server gives an agent new abilities. A registry makes each one a deliberate decision.

Without a registryWith a registry
Any server an agent names is reachableOnly servers you registered are known
Nobody reviews a new serverAn admin approves it before it goes live
Tool rules live only in agent codeEach server has its own allowed and denied tools
No record of what changedTool definitions are observed and reviewed

03

Register a server

The registry is in AI → Credentials & Keys, on the MCP Tool Server Registry card.

  1. 1

    Choose Register server

    It is at the top right of the card.

  2. 2

    Enter the Server name

    Use the same name your agents use for the server, such as jira. Policies refer to this name.

  3. 3

    Enter the Server URL

    It must be a valid https:// URL.

  4. 4

    Set Allowed tools

    List the tools agents may use on this server, separated by commas. Leave it blank to allow all of its tools.

  5. 5

    Set Denied tools

    Optionally list tools that are never allowed on this server.

  6. 6

    Decide on activation

    Leave Apply immediately off to send the server through approval, or turn it on if you can approve it yourself.

  7. 7

    Save

    The server appears in the registry.

AI → Credentials & Keys → MCP Tool Server Registry → Register server
2Server name
jira
3Server URL (https://…)
https://mcp.example.com/jira
4Allowed tools
search_issues, get_issue

Comma-separated. Blank = all.

5Denied tools
delete_issue

Comma-separated. Optional.

6Apply immediately
Activate without waiting for a separate approval review.Off
Save server
Name, URL, and the tools this server may expose.

04

The approval step

A server you ask to activate starts disabled and shows a Pending approval badge. It goes live when an admin approves the request.

From registration to live
  1. 1Register

    Status disabled, Pending approval

  2. 2Review

    An admin opens the approval

  3. 3Approve

    Status active

  4. 4Bind to a policy

    Allowed tool servers

Approvals are listed under AI → Audit. If you are an owner or admin and want to skip the wait, use Activate tool server immediately when you register.

05

Give each server its own tool rules

Server rules apply on top of the policy's rules. They are the right place for a rule that belongs to one server.

Server ruleEffect
Allowed toolsOnly these tools are accepted from this server
Denied toolsThese tools are never accepted from this server. A deny wins

One server, two teams

A Jira server exposes search, create, and delete tools. The registry denies delete for everyone. The support policy then allows only search and create. A request for delete is refused by the registry rule before the policy is considered.

06

Let a policy use the server

Registering a server makes it known. A policy decides who may use it.

  1. 1

    Open the policy

    Go to AI → Policies and open the policy bound to the agent.

  2. 2

    Add the server

    On Advanced, under Tool & modality restrictions, add the server's name to Allowed tool servers.

  3. 3

    Check Known tool servers

    The policy form lists the registered servers, so you can confirm the name.

07

The server URL must match

When a request names a server and carries its URL, the URL has to match the one you registered. Case, a default port, and a trailing slash do not count as differences.

That keeps a look-alike URL from standing in for a server you approved. A mismatch is refused with tool_server_url_mismatch.

08

Enable, disable, and edit

A server's row has the controls you need over time.

ActionWhat it does
DisableStops all use of the server at once. Requests that name it are refused as tool_server_disabled
EnableTurns the server back on
EditChange the name, URL, and tool lists
DeleteRemoves the server and its recorded tool definitions

09

Keep it as code

Registered servers can live in Terraform.

main.tf
resource "cloptima_llm_gateway_tool_server" "jira" {
  name               = "jira"
  server_type        = "mcp"
  server_url         = "https://mcp.example.com/jira"
  status             = "active"
  allowed_tool_names = ["search_issues", "create_issue"]
  denied_tool_names  = ["delete_issue"]
}

Activation follows the same approval rules as the console. Set apply_immediately to approve in the same apply when your role allows it.

10

If something goes wrong

Most problems are status or naming.

What you seeLikely causeFix
The server stays disabled with Pending approvalNobody has approved it yetApprove it under AI → Audit, or register again with Activate immediately
tool_server_unknownThe name in the request does not match a registered serverUse the registered name, or register the server
tool_server_disabledThe server is disabledEnable it
tool_server_not_allowedThe policy does not list the serverAdd it to Allowed tool servers
tool_server_url_mismatchThe request URL differs from the registered URLUpdate the agent, or edit the registered URL

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial