On this page
01
What you'll set up
The registry is your list of MCP servers that agents may use. In about ten minutes you will register a server, give it its own tool rules, route its activation through an approval, and let a policy use it.
- A registered MCP server with a name and URL
- Allowed and denied tools for that server
- An approval step before the server goes live
- A policy that is allowed to use it
Owners and admins register servers. You need a policy already bound to your agent's traffic.
02
Why register a server
An MCP server gives an agent new abilities. A registry makes each one a deliberate decision.
| Without a registry | With a registry |
|---|---|
| Any server an agent names is reachable | Only servers you registered are known |
| Nobody reviews a new server | An admin approves it before it goes live |
| Tool rules live only in agent code | Each server has its own allowed and denied tools |
| No record of what changed | Tool definitions are observed and reviewed |
03
Register a server
The registry is in AI → Credentials & Keys, on the MCP Tool Server Registry card.
- 1
Choose Register server
It is at the top right of the card.
- 2
Enter the Server name
Use the same name your agents use for the server, such as jira. Policies refer to this name.
- 3
Enter the Server URL
It must be a valid https:// URL.
- 4
Set Allowed tools
List the tools agents may use on this server, separated by commas. Leave it blank to allow all of its tools.
- 5
Set Denied tools
Optionally list tools that are never allowed on this server.
- 6
Decide on activation
Leave Apply immediately off to send the server through approval, or turn it on if you can approve it yourself.
- 7
Save
The server appears in the registry.
- 2Server name
- jira
- 3Server URL (https://…)
- https://mcp.example.com/jira
- 4Allowed tools
- search_issues, get_issue
Comma-separated. Blank = all.
- 5Denied tools
- delete_issue
Comma-separated. Optional.
- 6Apply immediately
- Activate without waiting for a separate approval review.Off
04
The approval step
A server you ask to activate starts disabled and shows a Pending approval badge. It goes live when an admin approves the request.
1Register
Status disabled, Pending approval
2Review
An admin opens the approval
3Approve
Status active
4Bind to a policy
Allowed tool servers
Approvals are listed under AI → Audit. If you are an owner or admin and want to skip the wait, use Activate tool server immediately when you register.
05
Give each server its own tool rules
Server rules apply on top of the policy's rules. They are the right place for a rule that belongs to one server.
| Server rule | Effect |
|---|---|
| Allowed tools | Only these tools are accepted from this server |
| Denied tools | These tools are never accepted from this server. A deny wins |
One server, two teams
A Jira server exposes search, create, and delete tools. The registry denies delete for everyone. The support policy then allows only search and create. A request for delete is refused by the registry rule before the policy is considered.
06
Let a policy use the server
Registering a server makes it known. A policy decides who may use it.
- 1
Open the policy
Go to AI → Policies and open the policy bound to the agent.
- 2
Add the server
On Advanced, under Tool & modality restrictions, add the server's name to Allowed tool servers.
- 3
Check Known tool servers
The policy form lists the registered servers, so you can confirm the name.
07
The server URL must match
When a request names a server and carries its URL, the URL has to match the one you registered. Case, a default port, and a trailing slash do not count as differences.
That keeps a look-alike URL from standing in for a server you approved. A mismatch is refused with tool_server_url_mismatch.
08
Enable, disable, and edit
A server's row has the controls you need over time.
| Action | What it does |
|---|---|
| Disable | Stops all use of the server at once. Requests that name it are refused as tool_server_disabled |
| Enable | Turns the server back on |
| Edit | Change the name, URL, and tool lists |
| Delete | Removes the server and its recorded tool definitions |
09
Keep it as code
Registered servers can live in Terraform.
resource "cloptima_llm_gateway_tool_server" "jira" {
name = "jira"
server_type = "mcp"
server_url = "https://mcp.example.com/jira"
status = "active"
allowed_tool_names = ["search_issues", "create_issue"]
denied_tool_names = ["delete_issue"]
}Activation follows the same approval rules as the console. Set apply_immediately to approve in the same apply when your role allows it.
10
If something goes wrong
Most problems are status or naming.
| What you see | Likely cause | Fix |
|---|---|---|
| The server stays disabled with Pending approval | Nobody has approved it yet | Approve it under AI → Audit, or register again with Activate immediately |
| tool_server_unknown | The name in the request does not match a registered server | Use the registered name, or register the server |
| tool_server_disabled | The server is disabled | Enable it |
| tool_server_not_allowed | The policy does not list the server | Add it to Allowed tool servers |
| tool_server_url_mismatch | The request URL differs from the registered URL | Update the agent, or edit the registered URL |