Monday, October 5, 2026

#1180 - OIC MCP Gateway - simple use case & monitoring

Introduction 

I've already posted on the MCP Gateway basics, now for a bit more detail. In this post I will cover the creation of a couple of gateways. I will also look at gateway monitoring.

The following project is the starting point - 

My job is to expose these integrations as tools and then protect them, via the gateway.

I will have 2 sets of agent clients - internal and external; therefore I will create 2 gateways.

The 3 integrations have already been exposed as tools -

Creating the Gateways

I have already exposed the OIC project as an MCP server and I have created an entry for it - 

I will also need a couple of security and business policies. 
For a start, I want to give the internal gateway access to all 3 tools, whereas the external gateway should only grant access to the RetrieveSRDetails tool.

Security Policies

Check out the generated rule - 

Now to the Internal Gateway - 

I check the following policies - 


I activate both gateways - 

Check out the gateway metadata, by clicking Run - 

The MCP gateway URL - this is what we need, when invoking the gateway from Postman.

Over to Postman - 

I connect to the internal gateway and see the tools on offer - 

I run the RetrieveSRDetails tool - 

"content": [ { "type": "text", "text": "{\n \"SrId\" : \"300000343241181\",\n \"SrNumber\" : \"SR314477\",\n \"Title\" : \"Fit1000 broken\",\n \"ProblemDescription\" : \"Our cross trainer just stopped working.
\",\n \"Severity\" : \"High\",\n \"Assignee\" : \"Claudia Monet\",\n
\"AssigneeEmailAddress\" : \"claudia.monet_etaj-dev25@oraclepdemos.com\"\n}" } ],


I run the createExternalSR tool - note, I set the country field to Ireland

   





"content": [
        {
            "type": "text",
            "text": "Tool 'SERVICE_REQUESTS_MCP_SERVER__CREATEEXTERNALSR'
is not allowed by policy 'business'.
reason: Customers from Ireland are not allowed."
        }
    ],

Looks good, the policies are being applied.

Now to the external gateway - 

Only 1 tool is available - 

Note the email in the response is masked -


"content": [
        {
            "type": "text",
            "text": "{\"SrId\":\"300000343241181\",\"SrNumber\":\"SR314477\",\"Title\":
\"Fit1000 broken\",\"ProblemDescription\":\
"Our cross trainer just stopped working. \",\"Severity\":\"High\",
\"Assignee\":\"Claudia Monet\",
\"AssigneeEmailAddress\":\"*****************************************\"}"
        }
    ], 


Gateway Monitoring 

Note how the business policy was applied on the request, thus no MCP Server / Tool was invoked.

Also note the instance ids. These are NOT the instance ids of the integrations which are eventually invoked - 


Back to the MCP Gateway instance activity stream - 

Summa Summarum

The MCP Gateway has been introduced in the 26.10 release of OIC, so please consider this as the first iteration of the product; later releases will naturally build on this, so watch this space!

 


























 

 

No comments: