Docs

Discovery

Discover and refresh the tools, resources, prompts, and data exposed through MCP servers.

Discovery is the background process that turns a registered endpoint into a populated catalog. A discovery run picks a connector — the generic MCP connector for anything reachable over HTTP/stdio, or a vendor-specific connector (GitHub today) as a fallback — resolves an auth token (from the OAuth token cache for auth_type: oauth servers, or from the matching Kubernetes Secret key for everything else, with a legacy spec.auth_token fallback), and calls the endpoint to list its tools, resources, and prompts. Results are ingested into the catalog as active rows, and an AI Graph edge (exposes_tool / exposes_resource) is created from the server to each one. If a tool's input schema looks like it takes a table/column argument, the ingest step also runs a seeding pass that infers a declarative arg-to-resource extractor and, for SQL-shaped tools, kicks off data enrichment to discover the underlying tables and columns asynchronously — including a name-based sensitivity tagger that flags likely PII, PHI, GDPR, SOX, or HIPAA columns for a human to confirm or correct.

Discovery runs both automatically and on demand. A scheduler ticks every 60 seconds and triggers a run for any server whose configured interval has elapsed (default 5 minutes, overridable per server, with auto-discovery itself toggleable off); a manual trigger is available per server. Every run is recorded with a status (running / completed / failed) and counts of tools, resources, and prompts found, browsable at /mcp-server-inventory and drillable per server at /mcp-server-logs.

Each completed run also produces a snapshot — a hash of the server's current tools and resources — which is compared against the previous snapshot to detect drift. When the hash changes, an activity entry is recorded and the change is surfaced at /mcp-drift: a diff between the current and previous tools/resources/prompts/capabilities hashes for a selected server, so an operator can see that an upstream MCP endpoint added, removed, or changed a tool since it was last discovered.

Reference

Features

Automated discovery
description
A scheduler checks every registered server once a minute and triggers a discovery run for any whose configured interval (default 5 minutes) has elapsed, unless auto-discovery is disabled on that server.
Manual refresh
description
An operator-triggered discovery run for one server, run immediately rather than waiting for the scheduler — used after registering new tools upstream.
Discovery status
description
The outcome of each discovery run — running, completed, or failed, with an error message on failure and counts of tools, resources, and prompts found on success.
Discovery logs
description
A per-server, filterable log of discovery activity (severity, logger name, message, correlation id) at /mcp-server-logs.
Inventory inspection
description
A table of every registered server's protocol version, transport type, auth type, and capability hash at /mcp-server-inventory.
Drift identification
description
Detects when a server's tools, resources, prompts, or capabilities changed since the last discovery run by comparing SHA-256 hashes of successive snapshots, and shows the before/after at /mcp-drift.

Interfaces

data-plane serves /mcp-servers
data-plane serves /mcp-server-inventory
data-plane serves /mcp-server-logs
data-plane serves /mcp-drift