Skip to main content
Every deployed agent gets one fixed URL for every tool action, no matter how many tools or providers sit behind it: the MCP gateway. Adding, removing, sharing, or restricting a tool is a configuration change — the agent is never redeployed. The gateway speaks the Model Context Protocol. Agents call it with JSON-RPC tools/list and tools/call, and it fans each call out to whichever backend implements that tool.

Connect an external server

Register a managed integration or your own running MCP server.

Deploy your own server

Upload source and let Nasiko build, harden, and run it.

Per-agent tool permissions

Control which connectors and tools an agent may use.

MCP gateway dashboard

Register connectors and set rules in the web app.

Two kinds of provider, one interface

Everyone using a shared connector connects with their own account. Sharing never shares the underlying login.

Agent credential

An agent is untrusted code serving many users. At deploy time Nasiko injects MCP_GATEWAY_TOKEN (and MCP_GATEWAY_URL) into the container. The agent sends that token on every gateway call. User identity still comes from the flow’s traceparent — the same strict attribution as model calls. See cost attribution. Two equivalent endpoints: JSON-RPC methods: initialize, ping, tools/list, tools/call.
A user session JWT is not accepted on /api/mcp. Management routes (/api/mcp/catalog, connectors, grants) use your login. The gateway JSON-RPC surface uses the deploy-time agent token.

The gateway endpoint

JSON-RPC tools/list and tools/call examples:
Tool names from custom MCP server connectors are namespaced {connector-id-prefix}__{tool_name}, so two connectors can’t collide. Managed toolkit tools keep their natural names (GMAIL_SEND_EMAIL, SLACK_POST_MESSAGE).

Blocked and approval-required calls

A tools/call can return a JSON-RPC error instead of a result:

Permissions

Every tool call resolves through two layers, in order:
  1. Reachability — can the calling user reach this connector? (They own it, it’s shared with them, or it’s a globally available toolkit.)
  2. Per-agent permission — is the connector enabled for this agent, and is this tool allowed, blocked, or gated behind approval?
Nothing needs configuring to grant an agent access to a connector its caller can already reach — access propagates the moment a connector is shared. Full model: per-agent tool permissions.

Management routes

Session-authenticated and access-controlled — everything the CLI and dashboard use: