Upstream authentication
Valid pairings:
none with none only; api-key and oauth each with shared or per-user. Defaults when credential type is omitted: none→none, api-key→shared, oauth→per-user. OAuth requires streamable-http.
Egress headers
Only
streamable-http tools can carry egress headers. Act-as headers require OIDC or HMAC verification and are not valid with OAuth upstream auth. Configure headers on Tools.
Discovered tools
Blocking denies the operation even if another rule would permit it. Status persists when the gateway observes the operation again. Only a restore returns it to
active.
Protocols
Also refer to Tools gateway concept for REST catalog egress.
Next steps
Add connections and attach them to Gateways:- Tools concept for credentials, catalogs, and reachability
- Tools to add tools, manage catalogs, and attach Gateways
- Tools gateway concept for the MCP ingress