tools/list and tools/call, and it fans each call out to whichever backend implements that tool.
Connect an external server
Register a managed integration or your own running MCP server.
Deploy your own server
Upload source and let Nasiko build, harden, and run it.
Per-agent tool permissions
Control which connectors and tools an agent may use.
MCP gateway dashboard
Register connectors and set rules in the web app.
Two kinds of provider, one interface
Everyone using a shared connector connects with their own account. Sharing never shares the underlying login.
Agent credential
An agent is untrusted code serving many users. At deploy time Nasiko injectsMCP_GATEWAY_TOKEN (and MCP_GATEWAY_URL) into the container. The agent sends that token on every gateway call. User identity still comes from the flow’s traceparent — the same strict attribution as model calls. See cost attribution.
Two equivalent endpoints:
JSON-RPC methods:
initialize, ping, tools/list, tools/call.
A user session JWT is not accepted on
/api/mcp. Management routes (/api/mcp/catalog, connectors, grants) use your login. The gateway JSON-RPC surface uses the deploy-time agent token.The gateway endpoint
JSON-RPCtools/list and tools/call examples:
{connector-id-prefix}__{tool_name}, so two connectors can’t collide. Managed toolkit tools keep their natural names (GMAIL_SEND_EMAIL, SLACK_POST_MESSAGE).
Blocked and approval-required calls
Atools/call can return a JSON-RPC error instead of a result:
Permissions
Every tool call resolves through two layers, in order:- Reachability — can the calling user reach this connector? (They own it, it’s shared with them, or it’s a globally available toolkit.)
- Per-agent permission — is the connector enabled for this agent, and is this tool allowed, blocked, or gated behind approval?
Management routes
Session-authenticated and access-controlled — everything the CLI and dashboard use:Related
- Artifact registry — MCP server packages as reusable artifacts
- Access control overview
