Docs

MCP Server Connection

Register and configure MCP servers and their credentials.

MCP Server Connection is the wizard that creates or edits the servers that MCP Server Mesh then lists — registration, not inventory. It runs as a full page at /mcp-connect/new and /mcp-connect/:id/edit (an earlier version lived in a modal; the modal is still used for the quick-edit affordance from the Mesh table). The base flow the product promises is "60 seconds, three fields" — server type, name, endpoint — with transport, auth type, and policy mode tucked behind a collapsed Advanced section that defaults to sensible values (HTTP, API key, auto-discover on, observe mode).

Selecting a vendor tile (GitHub, Postgres, AWS, Snowflake, Iceberg, or Custom) prefills the endpoint and, for AWS/Snowflake/Iceberg, reveals a structured credentials block instead of the legacy single opaque token. These vendor tiles are UX shortcuts for typing a known endpoint and credential shape — FaburAI does not ship vendor-specific MCP adapters; Custom accepts any MCP-compliant endpoint the same way the other tiles do under the hood. As the user types an endpoint, the form debounces 600ms and calls a reachability probe that does a plain TCP dial against the host and port — it confirms the URL resolves and is reachable, not that anything MCP-shaped is listening on the other end. An unreachable result is a warning, not a block: the connector can still be saved, and discovery retries once the endpoint comes up. New connections are capped at one MCP server for trial tenants; paid tenants have no cap enforced at this layer.

Structured credentials submitted through a vendor tile are persisted to the server's row and, when a Kubernetes client is available, synced best-effort into a K8s Secret that the vendor's MCP pod reads from — creating it if absent, merging new keys into it if it exists so operator-set keys the wizard doesn't manage survive. Values are AES-256-GCM encrypted before they reach the Secret whenever the DP has an encryption key configured; a missing key or missing cluster access is logged and skipped rather than failing the save, so the database row is always the source of truth even if the Secret sync lags or never runs. In edit mode, leaving a credential field blank means "keep the stored value," not "clear it" — only non-empty fields are sent.

Reference

Features

Connect new server
description
A vendor-tile picker (GitHub, Postgres, AWS, Snowflake, Iceberg, or Custom) that prefills endpoint and credential-field hints, on top of a bare form of server type, name, and endpoint for anything else.
Edit connection
description
Update an existing server's name, endpoint, transport, auth type, or credentials from /mcp-connect/:id/edit or the Mesh table's inline edit action; blank credential fields keep the stored value rather than clearing it.
Endpoint configuration
description
The server's URI, transport type (HTTP, WebSocket, or stdio), and — for stdio — the subprocess launch command.
Reachability validation
description
A debounced pre-submit check that TCP-dials the endpoint's host and port. It confirms the address is dialable, not that the endpoint speaks MCP; an unreachable result is a warning and does not block saving.
Credential handling
description
Either a single opaque auth token (legacy path, most vendor tiles) or a structured set of named credential fields (AWS, Snowflake, Iceberg) collected in the wizard and stored server-side.
Secret synchronization
description
Best-effort sync of structured credentials into a Kubernetes Secret the vendor's MCP pod reads from, encrypted at rest when a DP encryption key is configured. Skipped with a log line when no cluster is reachable; never blocks the save.

Interfaces

data-plane serves /mcp-connect/new
data-plane serves /mcp-connect/:id/edit