Skip to main content
MCP Gateway connects in two directions. Your agents reach other tools through it, and other platforms reach Atlan through it.
  • Add MCP servers behind the gateway. Start from a built-in integration, such as Linear, Notion, or Glean, or paste the URL of any remote MCP server. The gateway discovers the server’s tools, catalogs them, and serves them to every connected client.
  • Connect data platforms to Atlan. Add the gateway to Databricks or Snowflake as an MCP server, so their agents can use Atlan’s tools.
Everything starts in the Marketplace in Atlan. Marketplace page listing Linear, Miro, and Glean under In your workspaces, with Notion, Sentry, Granola, and Zendesk under Available to set up

Before you begin

  • You can manage the workspace the server will belong to. Everyone who can read that workspace can see the server’s tools, and everyone who can update it can run them.
  • The server speaks Streamable HTTP and is reachable from the internet. stdio servers and legacy HTTP+SSE servers are not supported.

Built-in integrations

Atlan already knows the settings of these servers. Each uses per-person OAuth: Atlan registers itself with the vendor automatically, and each person signs in with their own account. An agent can see only what that person can see in the vendor’s product.
1

Find the integration

In Marketplace, under Available to set up, select Set up on the integration. For Glean or Zendesk, enter your address.
2

Choose the workspace and add it

Choose the workspace that will own the server, confirm the Name and Display name, and select Add server.
3

Each person connects

Each person who wants to use it selects Connect on the server’s card and signs in at the vendor.
Glean and Zendesk can restrict access by network. If Atlan reports the server as unavailable with a correct address, ask the vendor’s administrator to allow connections from Atlan.
Try it. With Linear connected, ask your agent “File a Linear issue for the checkout timeout we just reproduced, assigned to me.” The call appears in Tool calls with the agent’s rationale.

Any custom MCP server

You aren’t limited to the built-in list. Paste the URL of any remote MCP server, whether a vendor’s or one your team runs. Atlan works out how the server signs in, shows only the form that server needs, and catalogs every tool it offers.
You paste the server URL, Atlan discovers how it signs in, you confirm the matching form, and the gateway catalogs every tool. No sign-in needs nothing; a token or key needs one shared credential; OAuth with automatic registration lets each person sign in; OAuth that needs an app asks an admin for a client id and secret.You paste the server URL, Atlan discovers how it signs in, you confirm the matching form, and the gateway catalogs every tool. No sign-in needs nothing; a token or key needs one shared credential; OAuth with automatic registration lets each person sign in; OAuth that needs an app asks an admin for a client id and secret.
Preview. Adding a custom server by URL is not enabled for every Atlan account. Built-in integrations are available without it.
1

Enter the URL

In Marketplace, under In your workspaces, select Add MCP server. Choose the Workspace, enter the Server URL, for example https://mcp.example.com/mcp, and select Continue.
2

Let Atlan discover the server

Atlan contacts the server without credentials and shows its progress: Reaching the host, Checking how it signs in, Finding its authorization server from the server’s OAuth metadata (RFC 9728, RFC 8414), and Choosing how Atlan signs in. Nothing is saved yet.
3

Confirm what Atlan found

What Atlan found shows the server’s name and sign-in method, and Atlan pre-fills the Name and Display name. Complete the form it shows:
4

Add the server

Select Add server, or Test and add for a credential. Atlan tests the credential first and refuses one the server rejects.

How the gateway catalogs tools

Once a server is added, the gateway connects to it, lists its tools, and stores each one in the catalog, usually within seconds. Every client then sees the tools as remote__<server-id>__<tool>, and agents can find them with semantic search. A server that uses each person’s account is not refreshed in the background, because no shared credential exists. Check its connection after signing in.

Connection status

Until a person connects to a per-person server, its tools are hidden from that person’s tools/list, and the result names the server so the client can prompt them.

Change or remove a server

  • Turn off a server to take it out of service without deleting it.
  • Change its URL to point at a new deployment. The gateway rediscovers its tools.
  • Remove for everyone deletes the server and all of its tools.
A server cannot be moved to another workspace. Add it again in the new workspace instead.

Connect data platforms to Atlan

Agents in Databricks and Snowflake can use Atlan’s tools too. Add MCP Gateway to the platform as an external MCP server. Its agents can then search your Registry, read artifacts, and call any server registered in Atlan, with every call permission-checked and audited.
Databricks (AI Playground and agents) and Snowflake (Cortex Agents and Cortex Code) add Atlan MCP Gateway as an MCP server. The gateway provides OAuth sign-in, a permission check, and session audit, and serves Atlan Registry tools plus your registered servers' tools.Databricks (AI Playground and agents) and Snowflake (Cortex Agents and Cortex Code) add Atlan MCP Gateway as an MCP server. The gateway provides OAuth sign-in, a permission check, and session audit, and serves Atlan Registry tools plus your registered servers' tools.
Preview. External MCP support is new in both Databricks and Snowflake and may need to be enabled for your account.
Both platforms use the same Atlan values: The platform can act as an Atlan agent, which suits a shared assistant where the audit shows the agent. It can also act as each person, where people see only what they can see in Atlan and the audit shows the person. To act as an agent, register an agent and keep its client_id and client_secret in your secret manager.
  1. Open AI Gateway > MCPs > Register MCP Server, choose a catalog and schema, name the service atlan, and create a connection.
  2. Set Host to api.atlan.com, Port to 443, and Base Path to /mcp.
  3. Choose an Auth type:
    • OAuth Machine-to-Machine acts as an Atlan agent. Enter its Client ID and Client secret, the token endpoint, and the scopes above.
    • Dynamic Client Registration acts as each person. Each person authorizes Atlan on first use.
  4. Select the tools agents may use, such as every tool starting with registry__.
  5. Grant EXECUTE on the service, plus USE CATALOG and USE SCHEMA.
  6. If serverless egress is restricted, allow api.atlan.com and auth.atlan.com.
Then, in AI Playground, add the MCP Servers tool, choose External MCP servers, and select atlan. See Register an MCP service.
Verify. Ask the platform’s agent “Find the Atlan skill that summarizes support tickets.” Confirm it calls registry__search_artifacts, then find the call in Atlan under Tool calls.

Security

  • Credentials are stored encrypted, resolved for each call, and never shown again or returned to an agent.
  • With per-person OAuth, each call uses the caller’s own grant, issued for the server’s exact URL. If a person hasn’t connected, the call is refused. The gateway never falls back to someone else’s credential.
  • The gateway refuses private, loopback, link-local, and cloud-metadata addresses, pins DNS for each connection, and does not follow redirects.

Next steps

Find and call tools

Let agents find the right tool with semantic search.

Track usage and audit

See every call across every integration.