Skip to main content

Roll out gateway clients

Rolling out the gateways means preparing access, sending users to the console, and supporting them once they connect. The console carries the deployment-specific endpoints and per-client setup guides, so you don't need to write client setup instructions for your users.

Prepare access​

Before you announce the rollout:

To check the experience before users do, follow the Connector Gateway quickstart with a test account.

Check network reachability​

Most MCP clients, such as Claude Code, Cursor, and VS Code, connect to the Connector Gateway from the user's machine. Claude on the web and Claude Desktop connect from Anthropic's cloud instead, so they work only when the gateway endpoint is reachable from the public internet. If your gateway sits on a private network, behind a VPN, or behind a firewall, tell users which clients to use.

Choose an authentication method​

  • Use browser-based sign-in for interactive clients. The session identifies the caller through your corporate identity provider.
  • Use a virtual API key for scripts, scheduled jobs, continuous integration, and other clients without a browser flow. Requests remain attributed to the key owner.

Point users to the console​

Send users the console URL for your deployment. They sign in with their corporate identity and find both gateways under Gateways:

  • Connectors: connect to the connectors granted to them on the Tools tab, then set up an MCP client from the Clients tab. The Clients tab has the gateway endpoint, a prompt that an AI coding assistant can use to configure itself, and setup guides for common clients.
  • AI Gateway: the Clients tab has the model gateway URL and setup guides for routing model traffic, and the API Keys tab issues virtual API keys.

In your announcement, list the connectors each group can use, any connectors that ask for a sign-in, and where users should ask for help.

Support users​

When a user can't reach a connector's tools, see Support users' connector access for the connection states users see and the checks to run.

Next steps​