Add an MCP server from the OIN catalog

Add a Model Context Protocol (MCP) server from the Okta Integration Network (OIN) without entering its connection details manually.

Before you begin

  • You have the super admin role or a custom role with the Manage third-party MCP Servers permission and resource type. See Use custom admin roles.

Procedure

  1. In the Admin Console, go to Applications and Resources > MCP Servers.
  2. Click Add from Catalog.
    The Okta Integration Network catalog opens.
  3. Find the MCP server that you want to add and click its tile.
  4. Click Add MCP Server. If multiple MCP servers are available, select the server that you want to add from the list.
    The Add MCP Server page opens, with the name, description, and resource URL prefilled from the catalog.
  5. Enter values for the org-specific properties that the MCP server requires, such as your account or instance identifier.
  6. Click Next.
  7. Review the authorization server details. To add more authorization servers, click Add another authorization server.

    You can't edit authorization server details that are populated automatically from the OIN catalog.

  8. Click Next.
  9. Select the authorization endpoint that you want to use.
  10. Add credentials for the MCP server.
    1. Enter a Client credentials name.
    2. Enter your Client ID and Client secret.

      You must configure the client as a confidential client using the authorization code flow, which requires a client ID and client secret.

    3. Select or add scopes. Scopes are automatically populated when available through metadata discovery.
    4. Click Add to add more scopes.
    5. Click Save.
  11. If you have Agent Gateway enabled, click Test credentials and discover tools to validate your credentials and view available tools.
  12. To create more client credentials sets, select Add and repeat the previous steps.
  13. Click Done and close.

    The MCP server appears on the MCP Servers page and can have one of the following statuses:

    • ACTIVE: The default status for newly added MCP servers.
    • INACTIVE: An admin has deactivated the MCP server and you can't use it for managed connections.
    • INVALID: The MCP server is missing authorization server information or contains corrupted metadata.

What to do next

Create a resource connection between the MCP server and an AI agent. See Connect AI agents to resources.