Setup IAM Domain Roles

This part includes the following steps:

  1. Create groups in the domain for each application role.
  2. Assign groups to application roles.
  3. Create Users in the domain.
  4. Assign users to groups.

Create Groups in the Domain for Each Application Role

  1. In the Model Context Protocol Servers page, select mcpserver, and then Domain.

  2. In the dbtools-mcp domain, go to User management and then Groups.

  3. Create the following groups:

    Group Name Application Role
    MCP_Administrators MCP_Administrator
    MCP_Operators MCP_Operator
    MCP_Users MCP_User
    MCP_All_Users Not Applicable

    For more information about creating groups in domains, see Creating a Group.

Assign Groups to Application Roles

  1. In the Model Context Protocol Servers page, select mcpserver, and then select the Roles tab.
  2. Click Assign Roles.
  3. For each Application Role:

    1. Click the Actions icon and select Manage groups.
    2. Click Assign groups.
    3. Select the required groups in the list of Available groups.
    4. Click Assign.

Create Users in the Domain

For the domain dbtools-mcp, create users.

See Create a User in an Identity Domain to learn how to create a user in an identity domain.

Assign Users to Groups

For the dbtools-mcp domain, assign users to groups.

See Adding a User to a Group to learn how to add a user to a group.

Note

You must have an Application Role assigned to use the MCP Server and to download Personal Access Tokens.