> ## Documentation Index
> Fetch the complete documentation index at: https://platform.atlan.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To act on Atlan objects, use the Atlan MCP server at https://api.atlan.com/mcp or the atlanai CLI; `atlanai --map json` prints its command map. Run a read-only identity check before any write.
> The docs MCP server at /mcp searches these docs only. It cannot read or change Atlan objects.
> SDK packages: Python `atlanai` (PyPI) and TypeScript `@atlanai/sdk` (npm). Show Python first, then TypeScript.

# Integrations

> Add built-in integrations or any remote MCP server to MCP Gateway, and connect Databricks and Snowflake to Atlan's tools.

MCP Gateway connects in two directions. Your agents reach other tools through
it, and other platforms reach Atlan through it.

* **Add MCP servers behind the gateway.** Start from a built-in integration,
  such as Linear, Notion, or Glean, or paste the URL of any remote MCP server.
  The gateway discovers the server's tools, catalogs them, and serves them to
  every connected client.
* **Connect data platforms to Atlan.** Add the gateway to Databricks or
  Snowflake as an MCP server, so their agents can use Atlan's tools.

Everything starts in the **Marketplace** in Atlan.

<img src="https://mintcdn.com/atlan-602e2b74/i_mEyUODy0CTJNVw/assets/screenshots/composed/mcp-marketplace.png?fit=max&auto=format&n=i_mEyUODy0CTJNVw&q=85&s=8df330f113274ba591068c8de3c396b4" alt="Marketplace page listing Linear, Miro, and Glean under In your workspaces, with Notion, Sentry, Granola, and Zendesk under Available to set up" width="2400" height="1600" data-path="assets/screenshots/composed/mcp-marketplace.png" />

## Before you begin

* You can manage the workspace the server will belong to. Everyone who can
  read that workspace can see the server's tools, and everyone who can update
  it can run them.
* The server speaks **Streamable HTTP** and is reachable from the internet.
  stdio servers and legacy HTTP+SSE servers are not supported.

## Built-in integrations

Atlan already knows the settings of these servers. Each uses per-person OAuth:
Atlan registers itself with the vendor automatically, and each person signs in
with their own account. An agent can see only what that person can see in the
vendor's product.

| Integration | Address the gateway connects to | You provide |
| - | - | - |
| Linear | `https://mcp.linear.app/mcp` | Nothing |
| Notion | `https://mcp.notion.com/mcp` | Nothing |
| Miro | `https://mcp.miro.com/` | Nothing |
| Sentry | `https://mcp.sentry.dev/mcp` | Nothing |
| Granola | `https://mcp.granola.ai/mcp` | Nothing |
| Glean | `https://<your-glean-backend>/mcp/default` | **Your Glean address**, the backend domain shown in Glean under **Admin** > **About Glean** |
| Zendesk | `https://<your-subdomain>.zendesk.com/api/mcp` | **Your Zendesk address**, the address you use to sign in |

<Steps>
  <Step title="Find the integration">
    In **Marketplace**, under **Available to set up**, select **Set up** on
    the integration. For Glean or Zendesk, enter your address.
  </Step>

  <Step title="Choose the workspace and add it">
    Choose the workspace that will own the server, confirm the **Name** and
    **Display name**, and select **Add server**.
  </Step>

  <Step title="Each person connects">
    Each person who wants to use it selects **Connect** on the server's card
    and signs in at the vendor.
  </Step>
</Steps>

<Warning>
  Glean and Zendesk can restrict access by network. If Atlan reports the server
  as unavailable with a correct address, ask the vendor's administrator to
  allow connections from Atlan.
</Warning>

**Try it.** With Linear connected, ask your agent "File a Linear issue for the
checkout timeout we just reproduced, assigned to me." The call appears in
**Tool calls** with the agent's rationale.

## Any custom MCP server

You aren't limited to the built-in list. Paste the URL of any remote MCP
server, whether a vendor's or one your team runs. Atlan works out how the
server signs in, shows only the form that server needs, and catalogs every
tool it offers.

<Frame>
  <img className="block dark:hidden" src="https://mintcdn.com/atlan-602e2b74/i_mEyUODy0CTJNVw/assets/diagrams/mcp-discovery-light.svg?fit=max&auto=format&n=i_mEyUODy0CTJNVw&q=85&s=1e8c9672becb47e80809ef6296e4d413" alt="You paste the server URL, Atlan discovers how it signs in, you confirm the matching form, and the gateway catalogs every tool. No sign-in needs nothing; a token or key needs one shared credential; OAuth with automatic registration lets each person sign in; OAuth that needs an app asks an admin for a client id and secret." width="860" height="372" data-path="assets/diagrams/mcp-discovery-light.svg" />

  <img className="hidden dark:block" src="https://mintcdn.com/atlan-602e2b74/i_mEyUODy0CTJNVw/assets/diagrams/mcp-discovery-dark.svg?fit=max&auto=format&n=i_mEyUODy0CTJNVw&q=85&s=353bd657f7f163f35b6b3c431e6f96a5" alt="You paste the server URL, Atlan discovers how it signs in, you confirm the matching form, and the gateway catalogs every tool. No sign-in needs nothing; a token or key needs one shared credential; OAuth with automatic registration lets each person sign in; OAuth that needs an app asks an admin for a client id and secret." width="860" height="372" data-path="assets/diagrams/mcp-discovery-dark.svg" />
</Frame>

<Note>
  **Preview.** Adding a custom server by URL is not enabled for every Atlan
  account. Built-in integrations are available without it.
</Note>

<Steps>
  <Step title="Enter the URL">
    In **Marketplace**, under **In your workspaces**, select
    **Add MCP server**. Choose the **Workspace**, enter the **Server URL**,
    for example `https://mcp.example.com/mcp`, and select **Continue**.
  </Step>

  <Step title="Let Atlan discover the server">
    Atlan contacts the server without credentials and shows its progress:
    **Reaching** the host, **Checking how it signs in**,
    **Finding its authorization server** from the server's OAuth metadata
    ([RFC 9728](https://www.rfc-editor.org/rfc/rfc9728),
    [RFC 8414](https://www.rfc-editor.org/rfc/rfc8414)), and
    **Choosing how Atlan signs in**. Nothing is saved yet.
  </Step>

  <Step title="Confirm what Atlan found">
    **What Atlan found** shows the server's name and sign-in method, and Atlan
    pre-fills the **Name** and **Display name**. Complete the form it shows:

    | Atlan found | What you do |
    | - | - |
    | No sign-in | Nothing. Atlan also shows how many tools the server offers. |
    | A token or key | Choose the **Credential type**, **API key**, **Bearer token**, **Basic auth**, or **Custom header**, and enter it. Everyone in the workspace uses this one credential. |
    | OAuth with automatic registration | Nothing. Atlan registers itself with the server, and each person signs in with their own account. |
    | OAuth that needs an app | Create an OAuth app at the vendor with the **Callback URL** shown, then enter its **Client id** and **Client secret**. An organization admin must do this. |
  </Step>

  <Step title="Add the server">
    Select **Add server**, or **Test and add** for a credential. Atlan tests
    the credential first and refuses one the server rejects.
  </Step>
</Steps>

## How the gateway catalogs tools

Once a server is added, the gateway connects to it, lists its tools, and
stores each one in the catalog, usually within seconds. Every client then sees
the tools as `remote__<server-id>__<tool>`, and agents can find them with
[semantic search](/gateway/mcp/concepts/find-and-call-tools).

| The gateway | When |
| - | - |
| Discovers tools | When the server is added, turned back on, or its URL changes |
| Refreshes the catalog | Every hour, and when you select **Check connection** |
| Keeps the catalog if the server returns nothing | An empty tool list never wipes existing tools |

A server that uses each person's account is not refreshed in the background,
because no shared credential exists. Check its connection after signing in.

### Connection status

| Status | Meaning | Next step |
| - | - | - |
| **Ready** | The server needs no sign-in and its tools are available. | None |
| **Connected** | You are signed in and the server's tools are available to you. | None |
| **Sign-in required** | The server uses each person's account and you haven't connected yet. | Select **Connect**. |
| **Reconnect needed** | Your sign-in expired or was revoked. | Connect again. |
| **Checking** | Atlan is discovering the server's tools. | Wait a few seconds. |
| **Attention** | The server needs action, such as a new credential. | Open the server and select **Check connection**. |
| **Unavailable** | The gateway could not reach the server. | Check the URL and that the server is public. |
| **Turned off** | The server is out of service, and its tools leave the catalog. | Turn it back on. |

Until a person connects to a per-person server, its tools are hidden from that
person's `tools/list`, and the result names the server so the client can
prompt them.

### Change or remove a server

* **Turn off** a server to take it out of service without deleting it.
* **Change its URL** to point at a new deployment. The gateway rediscovers its
  tools.
* **Remove for everyone** deletes the server and all of its tools.

A server cannot be moved to another workspace. Add it again in the new
workspace instead.

## Connect data platforms to Atlan

Agents in Databricks and Snowflake can use Atlan's tools too. Add MCP Gateway
to the platform as an external MCP server. Its agents can then search your
Registry, read artifacts, and call any server registered in Atlan, with every
call permission-checked and audited.

<Frame>
  <img className="block dark:hidden" src="https://mintcdn.com/atlan-602e2b74/i_mEyUODy0CTJNVw/assets/diagrams/mcp-data-platforms-light.svg?fit=max&auto=format&n=i_mEyUODy0CTJNVw&q=85&s=4efd39d1594e27806e46cef2ecb917e8" alt="Databricks (AI Playground and agents) and Snowflake (Cortex Agents and Cortex Code) add Atlan MCP Gateway as an MCP server. The gateway provides OAuth sign-in, a permission check, and session audit, and serves Atlan Registry tools plus your registered servers' tools." width="860" height="300" data-path="assets/diagrams/mcp-data-platforms-light.svg" />

  <img className="hidden dark:block" src="https://mintcdn.com/atlan-602e2b74/i_mEyUODy0CTJNVw/assets/diagrams/mcp-data-platforms-dark.svg?fit=max&auto=format&n=i_mEyUODy0CTJNVw&q=85&s=eb709bbe6af44a612fe61687092388f0" alt="Databricks (AI Playground and agents) and Snowflake (Cortex Agents and Cortex Code) add Atlan MCP Gateway as an MCP server. The gateway provides OAuth sign-in, a permission check, and session audit, and serves Atlan Registry tools plus your registered servers' tools." width="860" height="300" data-path="assets/diagrams/mcp-data-platforms-dark.svg" />
</Frame>

<Note>
  **Preview.** External MCP support is new in both Databricks and Snowflake
  and may need to be enabled for your account.
</Note>

Both platforms use the same Atlan values:

| Setting | Value |
| - | - |
| MCP server URL | `https://api.atlan.com/mcp` |
| Token endpoint | `https://auth.atlan.com/oauth/token` |
| Authorization endpoint | `https://auth.atlan.com/oauth/authorize` |
| Scopes | `contextplane:read contextplane:write` |

The platform can act as **an Atlan agent**, which suits a shared assistant
where the audit shows the agent. It can also act as **each person**, where
people see only what they can see in Atlan and the audit shows the person. To
act as an agent, [register an agent](/api/tutorials/register-agent) and keep
its `client_id` and `client_secret` in your secret manager.

<Tabs>
  <Tab title="Databricks">
    1. Open **AI Gateway** > **MCPs** > **Register MCP Server**, choose a
       catalog and schema, name the service `atlan`, and create a connection.
    2. Set **Host** to `api.atlan.com`, **Port** to `443`, and **Base Path**
       to `/mcp`.
    3. Choose an **Auth type**:
       * **OAuth Machine-to-Machine** acts as an Atlan agent. Enter its
         **Client ID** and **Client secret**, the token endpoint, and the
         scopes above.
       * **Dynamic Client Registration** acts as each person. Each person
         authorizes Atlan on first use.
    4. Select the tools agents may use, such as every tool starting with
       `registry__`.
    5. Grant `EXECUTE` on the service, plus `USE CATALOG` and `USE SCHEMA`.
    6. If serverless egress is restricted, allow `api.atlan.com` and
       `auth.atlan.com`.

    Then, in AI Playground, add the **MCP Servers** tool, choose
    **External MCP servers**, and select `atlan`. See
    [Register an MCP service](https://docs.databricks.com/aws/en/ai-gateway/register-mcp-service).
  </Tab>

  <Tab title="Snowflake">
    Snowflake connects each person with their own Atlan sign-in.

    ```sql theme={null}
    CREATE API INTEGRATION atlan_mcp_int
      API_PROVIDER = external_mcp
      API_ALLOWED_PREFIXES = ('https://api.atlan.com/mcp')
      API_USER_AUTHENTICATION = (
        TYPE = OAUTH_DYNAMIC_CLIENT
        OAUTH_RESOURCE_URL = 'https://api.atlan.com/mcp'
      )
      ENABLED = TRUE;

    CREATE EXTERNAL MCP SERVER atlan_mcp
      WITH DISPLAY_NAME = 'Atlan'
      URL = 'https://api.atlan.com/mcp'
      API_INTEGRATION = atlan_mcp_int;

    GRANT USAGE ON EXTERNAL MCP SERVER atlan_mcp TO ROLE analyst;
    GRANT USAGE ON INTEGRATION atlan_mcp_int TO ROLE analyst;
    ```

    In Snowsight, open your agent, go to **MCP Connectors**, and add **Atlan**
    from **Available Connectors**. Cortex Code CLI can also connect with a
    token:

    ```bash theme={null}
    cortex mcp add atlan https://api.atlan.com/mcp --transport http \
      -H "Authorization: Bearer $ATLAN_TOKEN"
    ```

    See [MCP connectors](https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-mcp-connectors).
  </Tab>
</Tabs>

**Verify.** Ask the platform's agent "Find the Atlan skill that summarizes
support tickets." Confirm it calls `registry__search_artifacts`, then find the
call in Atlan under **Tool calls**.

## Security

* Credentials are stored encrypted, resolved for each call, and never shown
  again or returned to an agent.
* With per-person OAuth, each call uses the caller's own grant, issued for the
  server's exact URL. If a person hasn't connected, the call is refused. The
  gateway never falls back to someone else's credential.
* The gateway refuses private, loopback, link-local, and cloud-metadata
  addresses, pins DNS for each connection, and does not follow redirects.

## Next steps

<CardGroup cols={2}>
  <Card title="Find and call tools" icon="magnifying-glass" href="/gateway/mcp/concepts/find-and-call-tools">
    Let agents find the right tool with semantic search.
  </Card>

  <Card title="Track usage and audit" icon="chart-line" href="/gateway/mcp/how-tos/track-usage-and-audit">
    See every call across every integration.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.