Tool visibility
Choose which of a server's tools AI agents can call. Disabled tools are hidden from every client, so agents never see them in their tool list.
Configure it on the server
You can also open Overall analytics > Settings, select one server and choose Tools. The section subtitle shows how many tools are exposed, for example 12 of 15 exposed.
Tool groups
Tools are grouped by what they do to the upstream system.
The Exposed to agents bar at the top shows how many tools in each group are enabled, for example Write 3 / 4.
Per-tool controls
Changes are drafts. Click Save settings in the footer to apply them.
Find a tool
Refresh the tool list
Click Refresh tools to fetch the server's current tool list. If the list is empty, the gateway hasn't fetched the tools yet; refresh, or connect OAuth first if the server needs it.
The Upstream tool changes card above the tool list watches for tools the server adds, removes or changes. See Tool change watch.
Per group and per user
To enable a tool, or require confirmation, only for some people, add a rule in Group and user rules. A rule can set each tool's Enabled, Confirmation and Justification to Inherit, On or Off for one smart group or one user.
Going further with the Policy Engine
When the Policy Engine is on for the MCP Gateway, the Tools section turns read-only and shows Controlled by Policy Engine; values saved through Edit anyway apply only if the Policy Engine is disabled (see What happens to classic settings). Tool availability then comes from two cards in Govern > Policy Engine > MCP Gateway:
Use both. An agent that cached an earlier tool list can still attempt a call, so hiding a tool alone is not enough. Edits join a shared draft and apply once you publish a revision.
Scenarios the cards support that the Tools switches cannot:
- Hide tools by what they do, across servers. Match the tool's
read_only,destructive,idempotentoropen_worldannotations, its tags or its risk, instead of switching tools off one by one. - Hide tools from some callers only. Combine a tool condition with smart groups, user email or agent name, for example hide write tools from one AI client.
- Hide resources and prompts. Besides tools, Discovery Visibility can deny MCP resources (by URI, template, name or MIME type) and prompts (by name), which have no switch in server settings.
priority 850
Related
- Human approval - what approvers see in each AI client.
- Tool change watch - review upstream tool changes before agents see them.
- Input aliases - translate mismatched tool inputs from AI clients.
- Security guardrails - scan tool inputs and results.
- Policy Engine overview - how cards, stages and priorities work.