Activate an MCP Gateway

After you add an MCP gateway, you must activate it. Then, you can start using it.

Instructions

  1. Open a project.
    1. In the navigation pane, select Projects.
    2. Select the project that contains the MCP gateway.
  2. In the left toolbar, select MCP Gateway .
  3. In the MCP gateway section, select the MCP gateway that you created.
  4. Click Actions Actions icon and then select Activate to activate the MCP gateway.
  5. Select the tracing level:
    • Production: Logs MCP gateway activity without capturing request or response payloads. Activity data is retained for 32 days. This selection is recommended for production environments.
    • Audit: Captures request and response payloads for troubleshooting. Activity data, including payloads, is retained for eight days. This selection is not recommended for production because payloads may contain sensitive data.
  6. Select the authorization mode to use to protect the MCP gateway.
    Option Description Recommended Use
    Use dedicated gateway authorization

    Uses MCP gateway-specific authorization with a dedicated audience and scopes for gateway-specific access control. Oracle Integration creates and manages a dedicated resource server for the MCP gateway.

    The dedicated resource server has an audience that uniquely identifies the gateway and scopes that allow clients to discover and invoke the tools exposed through that gateway.

    You must explicitly create or using an existing confidential application configured with the client credentials grant type in the Oracle Cloud Console and grant it the audience and scopes displayed by Oracle Integration for the gateway. See Get the Resource Server Scopes for the Confidential Application.

    This option provides stronger isolation and access control because:
    • Access can be granted for a specific gateway.
    • Credentials can be rotated or revoked without affecting clients of other gateways.
    • Audit activity can be associated with clients configured for the gateway.
    • A client does not automatically receive access to every gateway in the Oracle Integration service instance.

    If you delete the MCP gateway, the dedicated resource server is also deleted.

    • Production gateways
    • Gateways that expose destructive or sensitive tools
    • Users that require gateway-specific access control
    Use OIC integration authorization

    Uses the existing integration authorization for the service instance, allowing the MCP gateway to share the same authorization model as integrations in Oracle Integration. Oracle Integration does not create a dedicated resource server for the gateway.

    Clients invoke the gateway using the existing Oracle Integration service instance audience and integration scope (urn:opc:resource:consumer::all).

    This option provides the simplest setup because you use an existing Oracle Integration confidential application that already has the required integration scope. You do not need to explicitly create a confidential application.

    Access is controlled using the broader Oracle Integration service instance permissions rather than permissions that are unique to an individual MCP gateway.

    • Development environments
    • Test environments
    • Use cases where gateway-specific authorization isolation is not required

    This option requires less setup, but does not provide gateway-specific authorization isolation.

  7. Click Activate.

    Note:

    If you want to change the authorization mode for an activated MCP gateway, deactivate the gateway, change your selection, and reactivate the MCP gateway.

Get the Resource Server Scopes for the Confidential Application

If you selected the Use dedicated gateway authorization option when activating the MCP gateway, you must copy the two scopes for the MCP server resource name from the confidential application to use the client credentials grant type. These scopes are required to connect to the MCP gateway.

Use of the Use dedicated gateway authorization MCP gateway activation option requires that you use an existing confidential application or explicitly create a new one. You then explicitly add the resource server scopes to the client application. For instructions on creating a confidential application, see Complete Prerequisites: Create and Activate the Client Application.

  1. In the navigation pane, click Projects.
  2. Select your project.
  3. In the left navigation pane, select MCP Gateway .
  4. In the MCP gateways section, select the MCP gateway.
  5. Click Actions Actions icon and then select Run.
    The MCP Gateway run details panel opens, showing the created MCP server resource name.
  6. Copy the mcp_resource_server_NAME value:
    mcp_resource_server_NAME=OIC_instance_name-
    axkbv4ifb37h-px-pplMCPGW_TEST_MS|GW_AWS_FINDDOMAIN|1.0
  7. Sign in to the Oracle Cloud Console.
  8. Go to your confidential application
  9. Click the OAuth configuration tab.
  10. Click Edit OAuth configuration.
  11. Scroll down to the Resources section, and click Add Scope.
  12. Search for the resource server.
  13. Scroll down and select the resource server for the MCP gateway.

    “Add scope” dialog with a populated search field and one selected result. The result describes a resource server for an MCP gateway.

  14. Copy the two gateway-specific scopes that were created.


    The Resources section shows the Add scope and Remove buttons. Under Scope, the two scopes are listed.

    For this example:

    https://OIC_instance_name.oraclecloud.com:443/MCPGW_TEST_MS/GW_AWS_FINDDOMAIN/1.0/tools:list
    https://OIC_instance_name.oraclecloud.com:443/MCPGW_TEST_MS/GW_AWS_FINDDOMAIN/1.0/tools:call
  15. Click Submit.
  16. When connecting to the MCP gateway (for this example, in Postman), you specify the client ID and client secret for the confidential application, along with the two copied scopes.


    OAuth 2.0 authorization settings showing the client ID and secret, and the two scopes. The client authentication is set to “Send as Basic Auth header.” Authorization data is added to request headers.