What the gateway records
The gateway records two things: the session an agent opens and each tool call made inside it. Calls to Atlan platform tools and calls to your registered servers are recorded the same way.Session
Opened once per task with
registry__initialise. Holds the agent’s stated
objective, the client and version, the MCP protocol revision, and who
opened it.Tool call
One row per call, ordered within its session. Holds the tool, the server,
the rationale, the outcome, and the duration.
Arguments and results are never stored. Tool inputs often carry
credentials, customer records, or prompts, and outputs carry whatever the
server returned. The audit trail records which tool ran, for whom, why, and
how it ended. It does not record the data that passed through.
See usage in the MCP Gateway studio
Open the MCP Gateway studio and choose a workspace, or All workspaces.1
Check gateway health and volume on Overview
Overview shows Servers in service, Tools available,
Tool calls · 7 days with the failure rate, and
Sessions · 7 days. Below them are a Tool calls, last 14 days chart,
the Most-called tools, Recent sessions, and a
Needs attention list of servers that are disconnected or waiting for
sign-in.
2
Review every call on Tool calls
Tool calls lists each call newest first, with When, Tool,
Why, Outcome, Time, Session, and By. Filter by outcome
(All, Failed, Succeeded) or by server to audit one MCP server
across every agent that used it. The page shows the call count, failures,
and the Median and p95 duration.
3
Replay one agent's work on Sessions
Sessions lists each session’s Objective, Client,
Opened by, and Opened time. Open a session to read its calls in
the order the agent made them.
Answer common audit questions
Query the audit trail programmatically
Sessions and calls are Registry artifacts of kindmcp_session and
mcp_session_message, so you can read them with the same tools and APIs as
any other artifact.
- REST: count calls per day
- MCP: read calls from an agent
Use Aggregate artifacts of a kind to
build usage reports:Each result group holds one day and its call count. Aggregates group by
shared artifact fields such as
created_at. To break calls down by
server_slug, tool_name, or outcome, read the call rows.traceparent in the request’s _meta. The gateway stores it on the call and
passes it on to the downstream server.
Who can see the audit trail
Sessions and calls follow workspace access. People and agents can read the records in workspaces they can read. A session opened by a person lives in the account’s root workspace.Limits
- Recording is best-effort. If a record cannot be written, the tool call still succeeds, and that call is missing from the trail.
- Calls are recorded only when made inside a verified session. The gateway
refuses a call with no
session_id, exceptregistry__initialise. - The trail does not include tool arguments or tool output.
Next steps
Connect a client
Open a session and start recording calls.
Find and call tools
Send the session and rationale fields on every call.