Skip to main content

Introduction to the MCP Gateway

The MCP Gateway sits between your AI apps and the MCP servers they call. Users connect their AI app to a Quilr gateway URL instead of the server itself, and every tool call is checked against your tool rules and guardrails, then logged with the user, the agent and the result.

Your AI app
Claude, ChatGPT, Cursor, VS Code
Connects to a Quilr gateway URL
QuilrAI MCP Gateway
Tool rules and guardrails
Access by agent, group and user
Logs, analytics, health
MCP servers
Remote servers from the MCP Library
Your own servers and APIs
Local packages on the user's computer
QuilrAI

Key concepts​

TermWhat it is
MCP serverThe unit you configure. It holds its connection, sign-in, tools, guardrails and rules. Add one with Add MCP server or from the Library.
Quilr gateway URLThe address agents call for one server, for example https://mcpgateway.quilr.ai/github/mcp. The gateway calls the server's upstream URL.
OneMCPOne URL that serves every MCP a user may use. See OneMCP.
Allowed agentAn AI client, matched by its user-agent keyword. You choose which servers each agent may reach. See Agents Configuration.
User dashboardWhere users sign in at mcpgateway.quilr.ai, connect their accounts and copy their URLs.

New servers start with their tools turned off, so nothing is reachable until you enable it.

The MCP Gateway page​

Go to Settings > AI Gateway > MCP Gateway.

ButtonWhat it opens
Overall analyticsThe MCP Gateway workspace for all servers, on the Analytics tab
OneMCP endpointOneMCP settings. See OneMCP.
LibraryThe MCP Library. A count shows pending install requests from users.
Allowed AgentsWhich AI clients may connect, and which servers each one sees
Add MCP serverThe Add MCP drawer. See Adding MCP Servers.
...Connections (who has connected to which server) and ZIA integration (see Web Search Policy)
Summary tileShows
Tool callsCalls in the period, the share that came through OneMCP, people calling, tools called, success rate
EstateServers that are Serving, Awaiting connection or have No tools, and how many are enabled or disabled
Tools reachableTools agents can call, with Scoped rules, OAuth servers and the Library queue
Stopped by guardrailsCalls the gateway refused, Guardrail flags, Failed calls, p95 latency

Click a row on a tile to filter the server list or open the matching view.

BannerAction
N OAuth servers need an administrator connection before their tools can be discovered.Review all filters the list to those servers. With one server, the button reads Connect and the server name.
N quick fixes could prevent failed tool callsReview fixes opens the quick fixes drawer. See Input Aliases.

Below the banners, Elsewhere links to Inventory & analytics, the User dashboard and this Documentation. The server list has All, Local, Remote and API tabs, Search servers and a Filter for state, auth, source and runtime.

The server card​

Each configured server has a card.

AreaWhat it shows
HeaderName, System, Library or Local package tag, slug and description
EndpointsQuilr gateway URL (copy it for clients) and the Upstream URL, with upstream p95 and failures
StatusServing, Awaiting connection, No tools found or Disabled, plus transport and auth
ChipsTools, Guardrails, Scoped rules, Token saving. Each opens that section.
ActionsShow tools, Uninstall, and the enable toggle
TrafficCalls over time, users, tokens saved, top tools
InspectLogs (the server's activity), Open in Inventory
ConfigureGeneral, API (API servers only), Guardrails, Token Saving, Tools, Group & User Rules

A server waiting for an administrator OAuth sign-in shows Connect OAuth on its card.

The workspace​

Overall analytics and every Inspect and Configure button open the MCP Gateway workspace. Select one or more servers with the server picker, and change the period at the top.

TabWhat it shows
AnalyticsTool calls, Blocked, Guardrail flags, Via OneMCP, Tokens saved, Success, P95 latency, Users, Servers; calls over time and usage by server
ActivityTool calls (one row per call), Interactions (calls grouped into conversations), Findings (guardrail detections)
ConnectionsWhich users have connected to which servers, and their tool calls
HealthGateway verdict, Rejected requests, Access denied, Auth challenges, OAuth refreshes, Upstream server errors, and rejection reasons. Covers the whole gateway.
SettingsThe server configuration. Available for one server at a time.

Settings sections​

Sections vary by server. Edits are drafts until you click Save settings.

SectionWhat you set
GeneralName, upstream sign-in, custom headers, Access Control, Claims forwarding, Web Search Policy (QuilrAI Web Search only), Uninstall
APIBase URL, spec and access rules of an API MCP
PermissionsOAuth Permissions: the scopes the connection requests (OAuth servers with selectable scopes)
ToolsTool visibility, Human approval, Tool Change Watch
GuardrailsSecurity Guardrails on tool arguments and tool results
Token savingToken Saving strategies
Input aliasesInput Aliases: translate mismatched inputs from AI clients
Group & User RulesGroup & User Rules: overrides for a smart group or a single user
API tokensAPI Tokens for direct connections (not on OAuth servers)
Policy Engine

When the Policy Engine is on, Settings shows Policy Engine active and marks Tools, Guardrails, Token saving and Group & User Rules with its icon. Those sections follow published policies instead of these settings. General and API tokens are still managed here.

Next steps​