Monday, October 5, 2026

#1181 - OIC MCP Gateway fronting AI DB MCP Server

Introduction 


This post details how easy it is to use the new OIC MCP Gateway to govern access to AI DB based tools. Justt enable the AI DB MCP server and add a couple of tools!

I already have one tool available in the DB; this queries purchase orders in my orders table.


I can list the available tools, using the following SQL -



This tool is one I used in a previous post on AI DB Private Agent Factory.

Net, net - I have at least 1 tool in the DB; mcp server is also enabled -

The MCP Server URL format for AI DB is as follows - 

https://dataaccess.adb.<region-identifier>.oraclecloudapps.com/adb/mcp/v1/databases/<database-ocid>

I use this in the OIC MCP Gateway - MCP Server configuration page -

Note the security policy I selected -API Key Based Authentication.

This is purely for a quick test. I get the key as follows - Postman POST request - https://dataaccess.adb.us-phoenix-1.oraclecloudapps.com/adb/auth/v1/databases/myDB OCID/token

Request body - 

{
  "grant_type": "password",
  "username": "my DB User",
  "password": "my DB password"
}
 
This gives me the token I can use in the OIC MCP Server configuration -


Now to creating a new tool in AI DB. Remember our DB table, orders? I'll create a PLSQL based tool that will create a row in that table. 

First the PLSQL function - 

Now the PLSQL to create expose it as a tool - 

Refresh the MCP Server connection in OIC - 

Here is the tool payload, I'll create a business policy to deny large orders - 

I now update the Internal MCP Gateway to include the new AI DB MCP Server - 

In postman - I test the new tool, via the Internal Gateway - 

I enter the order details - 

I run, and then check for a new row in the DB table, orders -

I now try with an order over 10k.

 








"content": [
{"type": "text",
"text": "Tool 'AI_DB_MCP_SERVER__CREATE_ORDER_TOOL'
is not allowed by policy 'business'.
reason: Order price exceeds the maximum allowed."
}
],
"isError": true
}

 

Summa Summarum

The OIC MCP Gateway is a compelling addition to the OIC toolkit, and please note, this gateway is not just for OIC based MCP servers. The example above is for an AI DB based MCP server, but please consider this as just a placeholder for any standard 3rd party (in respect of OIC), MCP server.









#1180 - OIC MCP Gateway - simple use case & monitoring

Introduction 

I've already posted on the MCP Gateway basics, now for a bit more detail. In this post I will cover the creation of a couple of gateways. I will also look at gateway monitoring.

The following project is the starting point - 

My job is to expose these integrations as tools and then protect them, via the gateway.

I will have 2 sets of agent clients - internal and external; therefore I will create 2 gateways.

The 3 integrations have already been exposed as tools -

Creating the Gateways

I have already exposed the OIC project as an MCP server and I have created an entry for it - 

I will also need a couple of security and business policies. 
For a start, I want to give the internal gateway access to all 3 tools, whereas the external gateway should only grant access to the RetrieveSRDetails tool.

Security Policies

Check out the generated rule - 

Now to the Internal Gateway - 

I check the following policies - 


I activate both gateways - 

Check out the gateway metadata, by clicking Run - 

The MCP gateway URL - this is what we need, when invoking the gateway from Postman.

Over to Postman - 

I connect to the internal gateway and see the tools on offer - 

I run the RetrieveSRDetails tool - 

"content": [ { "type": "text", "text": "{\n \"SrId\" : \"300000343241181\",\n \"SrNumber\" : \"SR314477\",\n \"Title\" : \"Fit1000 broken\",\n \"ProblemDescription\" : \"Our cross trainer just stopped working.
\",\n \"Severity\" : \"High\",\n \"Assignee\" : \"Claudia Monet\",\n
\"AssigneeEmailAddress\" : \"claudia.monet_etaj-dev25@oraclepdemos.com\"\n}" } ],


I run the createExternalSR tool - note, I set the country field to Ireland

   





"content": [
        {
            "type": "text",
            "text": "Tool 'SERVICE_REQUESTS_MCP_SERVER__CREATEEXTERNALSR'
is not allowed by policy 'business'.
reason: Customers from Ireland are not allowed."
        }
    ],

Looks good, the policies are being applied.

Now to the external gateway - 

Only 1 tool is available - 

Note the email in the response is masked -


"content": [
        {
            "type": "text",
            "text": "{\"SrId\":\"300000343241181\",\"SrNumber\":\"SR314477\",\"Title\":
\"Fit1000 broken\",\"ProblemDescription\":\
"Our cross trainer just stopped working. \",\"Severity\":\"High\",
\"Assignee\":\"Claudia Monet\",
\"AssigneeEmailAddress\":\"*****************************************\"}"
        }
    ], 


Gateway Monitoring 

Note how the business policy was applied on the request, thus no MCP Server / Tool was invoked.

Also note the instance ids. These are NOT the instance ids of the integrations which are eventually invoked - 


Back to the MCP Gateway instance activity stream - 

Summa Summarum

The MCP Gateway has been introduced in the 26.10 release of OIC, so please consider this as the first iteration of the product; later releases will naturally build on this, so watch this space!