Hosted MCP availability

Understand the separate release boundary for remote third-party MCP connections.

Updated 2026-09-22 Read as Markdown
On this page

Current status

Hosted remote MCP is implemented in the hosted service, and its security review was completed in September 2026. Availability still depends on the workspace and deployment configuration, the remote server and authentication flow, and the supported client. Confirm those details before planning a production connection; this is not a blanket compatibility claim for every MCP server or appliance.

What is different from local MCP

A local stdio gateway wraps a command on the user’s machine. Hosted MCP handles a remote server and its credentials through a different trust and transport boundary. Local wrapper commands do not configure that remote path.

The account MCP connector at /mcp/account reads Kastra data. A working account connector does not prove that a third-party hosted MCP connection is available.

Available path today

Use local MCP governance for a supported local server. For a remote requirement, contact Kastra with the server, authentication method, intended tools, and approval needs. A catalog logo should be read as presentation metadata, not as a tested commercial integration.

Connect and verify a remote server

In Connections → MCP servers, an authorized administrator registers the remote server and its supported API-key or OAuth authentication. Complete the downstream authorization, refresh the tool catalog, and use the server-specific Kastra proxy URL in the client.

The governed endpoint is /mcp/proxy/{serverID}. Its OAuth scope is kastra.mcp.proxy, with authorization bound to that server; an account-read grant is not sufficient. Verify discovery, an allowed call, a denied call and the required approval flow before exposing write-capable tools. Inspect decision records and disconnect or revoke the connection when it is no longer needed.

Self-hosted remote MCP credential custody and network dependencies require separate qualification. The assisted appliance pilot does not establish this broader compatibility.