Skip to main content
Feedback

Organizational catalog

The organizational catalog in MCP Gateway is the curated list of MCP servers your organization has reviewed and approved for use. Every MCP server passes through the organizational catalog before reaching a profile or a user. Admins control which servers are available to the organization at one level.

How servers reach the organizational catalog

The organizational catalog draws from three sources of MCP servers, all unified in one approved list:

  • Public MCP servers from third-party providers: Admins add individual MCP servers published by third parties. For example, an official MCP server from Asana, GitHub, or Notion. Each server is added manually with its connection config.
  • The Custom MCP server registry: MCP Gateway connects to a registry of public MCP servers, so admins can pick from a curated set without entering connection details manually.
  • Hosted MCP servers: MCP servers hosted inside MCP Gateway can be published into the organizational catalog automatically, with their runtime URL pre-filled.

Sandbox analysis and risk scoring

Before approving a server, admins can run it through the MCP evaluation sandbox. The sandbox provisions the server in isolation and runs an LLM-driven risk scoring analysis on every tool. The sandbox writes per-tool risk scores, written reasons, and behavior tags back to the catalog item.

The Organizational Catalog page in MCP Gateway user interface surfaces the latest analysis date for each item and lets admins filter to show only analyzed items. This page supports clicking into an item to see the tool-by-tool scores before making an approval decision.

On this Page