> ## Documentation Index
> Fetch the complete documentation index at: https://platform.atlan.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> To act on Atlan objects, use the Atlan MCP server at https://api.atlan.com/mcp or the atlanai CLI; `atlanai --map json` prints its command map. Run a read-only identity check before any write.
> The docs MCP server at /mcp searches these docs only. It cannot read or change Atlan objects.
> SDK packages: Python `atlanai` (PyPI) and TypeScript `@atlanai/sdk` (npm). Show Python first, then TypeScript.

# Supported features and limits

> The MCP capabilities, transports, credential types, and limits Atlan MCP Gateway supports today.

Use this page to check whether MCP Gateway fits your clients and servers
before you connect them.

## Client to gateway

| Capability | Support |
| - | - |
| Transport | Streamable HTTP at `https://api.atlan.com/mcp` |
| MCP protocol revisions | `2026-07-28` (stateless, no handshake) and `2025-11-25` (with `initialize`), on the same URL |
| Authentication | OAuth 2.1 with protected-resource discovery ([RFC 9728](https://www.rfc-editor.org/rfc/rfc9728)), or an `Authorization: Bearer` token |
| `tools/list`, `tools/call` | Supported |
| Progress notifications and cancellation | Relayed between the client and the downstream server |
| Trace context | A W3C `traceparent` in `_meta` is recorded and forwarded downstream |
| `prompts/list`, `prompts/get` | Supported for Atlan's own authoring recipes |
| `resources/list`, `resources/read` | Supported for Atlan's own resources under `atlan://defaults/` |
| Standalone GET/SSE stream | Not supported |
| `notifications/tools/list_changed` | Not sent. Run `tools/list` again to see catalog changes. |
| Sampling, elicitation, and tasks | Not supported |

## Gateway to your MCP servers

| Capability | Support |
| - | - |
| Transport | Streamable HTTP over `https://` or `http://` |
| stdio servers and legacy HTTP+SSE servers | Not supported |
| Servers hosted by Atlan | Not supported. Atlan connects to a server you run. |
| Tools | Discovered, catalogued, and proxied |
| Prompts and resources from your servers | Not proxied |
| Private network addresses | Blocked. Loopback, private ranges, link-local, and cloud metadata addresses are refused, and redirects are not followed. |
| One server per URL | Registering the same URL twice is refused. |

## Credentials for your servers

| Credential | How the gateway uses it |
| - | - |
| None | Calls the server without credentials. |
| Bearer token | Sends it in `Authorization`, or in a header you name. |
| API key | Sends it in the header you name, with an optional prefix. |
| Basic auth | Sends it in `Authorization`. |
| OAuth 2.0 client credentials | The gateway gets and renews the access token. The client secret never reaches the MCP proxy. |
| Per-user OAuth | Each person connects their own account. The gateway discovers the server's sign-in and registers itself automatically, using PKCE. |

A server uses either one shared credential or per-user OAuth, not both.
Certificate and SSH-key credentials are not supported. The gateway injects a
single header per server.

## Governance

| Capability | Support |
| - | - |
| Tool namespacing | `registry__`, `extension__<provider>__`, and `remote__<server-id>__` prefixes |
| Discover versus run | Reading a workspace lets you see its servers' tools. Updating it lets you run them. |
| Enable or disable | Per server. A disabled server's tools leave the catalog. |
| Per-tool and per-agent allowlists | Not available |
| Session and call audit | Every call inside a session, with rationale, outcome, and duration |
| Argument and output capture | Not stored, by design |
| Rate limits | Per account and per account per server. A refusal returns `-32003` with `retry_after_seconds`. |

## Catalog limits

| Limit | Value |
| - | - |
| Automatic catalog refresh | Every hour, and on register, test, or refresh |
| Downstream call timeout | 10 seconds by default |
| Tools discovered per server | Up to 10,000 |
| Tool list size per server | Up to 8 MiB |
| Tool name pattern | `^[a-zA-Z0-9_-]{1,128}$` |

## Errors your client may see

| Error | Meaning |
| - | - |
| `-32602` with `reason: uncatalogued` | The tool is not in the catalog. Run `tools/list` again. |
| `-32003` with `data.reason` | Access was refused. `never_connected` and `needs_reconnect` mean you need to connect your account. `token_rejected` and `audience_mismatch` mean the credential does not match the server. |
| `-32003` with `rate_limited` | Wait for `retry_after_seconds`, then retry. |
| `session_id is required` | Call `registry__initialise` and pass its `session_id`. |

When a server needs your sign-in or cannot be reached, the gateway drops its
tools from `tools/list` and names it in the result's `_meta`, so the rest of
the catalog still works.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.