Add a Model Context Protocol (MCP) server by manually entering its connection details and credentials.
Before you begin
- You have the super admin role or a custom role with the Manage third-party MCP
Servers permission and resource type. See Use custom admin
roles.
Procedure
-
In the Admin Console, go to .
-
Click Add MCP Server.
The Add MCP Server page opens.
-
Enter a name, description, and base URL for the MCP server.
Note:
You can't change the base URL after you configure the MCP server. To use a different URL,
delete the MCP server entry and create a new one.
-
Click Next.
-
Add an authorization server.
Authorization server details are automatically populated when available through metadata
discovery.
-
Enter an Issuer.
-
Enter an Authorization endpoint URL.
-
Enter a Token endpoint URL.
-
To add more authorization servers, click Add another authorization server and repeat the previous step.
-
Click Next.
-
Add credentials for the MCP server.
-
Enter a Client credentials name.
-
Select a client registration type.
-
If you select Manual, enter your Client ID and Client secret.
You must configure the client as a confidential client using the authorization code flow, which requires a client ID and client secret.
-
If you select Dynamic Client Registration, Okta registers a client
with the provider and populates the credentials.
You can't switch to another registration type afterward.
-
Select or add scopes. Scopes are automatically populated when available through metadata
discovery.
-
Click Add to add more scopes.
-
Click Save.
-
If you have Agent Gateway enabled, click Test credentials and discover tools to validate your credentials and view available tools.
-
To create more client credentials sets, click Add and repeat the previous steps.
-
Click Done and close.
The MCP server appears on the MCP Servers page and can have one of the following statuses:
- ACTIVE: The default status for newly added MCP servers.
- INACTIVE: An admin has deactivated the MCP server and you can't use it for managed connections.
- INVALID: The MCP server is missing authorization server information or contains corrupted metadata.
What to do next
Create a resource connection between the MCP server and an AI agent. See Connect AI agents to resources.