Skip to main content

Support users' connector access

Users reach a connector's tools through a connection that they create in the console. The console guides them through connecting, signing in, and choosing tools, so you don't need to document those steps for them. This guide explains what users see, so you can prepare your rollout and diagnose access problems.

The Connector Gateway serves a connector's tools to a user's MCP clients only when all of these hold:

  1. The connector is Verified.
  2. The connector policy grants the user access.
  3. The user has connected to the connector and hasn't paused it.

You control the first two. The third is the user's choice, and their connection applies to every client that signs in to the gateway as them.

Where users manage connections​

Users manage connections in the console's user experience, under Connectors in the Gateways group. The Tools tab lists the connectors granted to them: connectors they've connected to appear under Enabled, and the rest appear under Available.

To see what a user sees, open the account menu and choose User under Experience. The user experience shows the connectors granted to your own account, so use a test account in the same groups as the user to reproduce their view.

Connection states​

A connector's detail page shows the user a status badge and the actions available for it:

StatusWhat it meansUser action
None (Available)The user hasn't connected. No tools are served.Connect
ConnectedThe gateway serves the connector's tools.Pause
PausedTools are hidden. The user's tool choices are kept.Resume
Reconnect requiredThe stored sign-in is expired or unusable. Calls fail.Reconnect

In every connected state, Disconnect removes the connection and the user's tool choices, and moves the connector back to Available.

Sign-in on connect​

The connector's Access section tells the user whether connecting needs a sign-in:

  • Company SSO required: the connector uses the Upstream identity provider authentication type. Selecting Connect opens a sign-in window, and the gateway stores the resulting credential for that user's calls.
  • No authentication required or Managed credential: the connector connects immediately.

Changing a connector identity provider's scopes or client ID requires every user of that provider to reconnect. Tell users before you make the change. See How users authorize connectors.

Tool choices​

On a connector's detail page, users can turn off individual tools, grouped into Destructive tools, Read-only tools, and Other tools. These choices narrow the tools the connector policy grants; they can't add tools. The gateway hides turned-off tools from the user's clients and rejects calls to them.

When a user reports a missing tool on a connected connector, ask them to check their tool choices on its detail page first.

When changes take effect​

The gateway reads connections and policies on every request, so connecting, pausing, tool choices, and your grant changes apply to the user's next tool list or tool call. Most MCP clients keep the tool list from when they connected. If a client still shows old tools, the user should refresh its tool list or restart the client.

Check a user's access​

When a user can't reach a connector's tools, work through these checks:

  1. Is the connector listed for the user? If their Tools tab doesn't show it, or shows "No connectors available to you yet", check the connector's status and its connector policy. In structured mode, the user must belong to a granted group or one of its subgroups.
  2. Is the connection active? Ask for the connector's badge. Available or Paused means no tools are served; Reconnect required means the user must sign in again.
  3. Are calls reaching the connector? The connector's Activity tab lists recent calls with the User and an Outcome of Allowed or Denied. A denied call points to the policy; no call at all points to the client configuration or connection.

For gateway-side causes, such as a connector the gateway withholds, see Troubleshooting in the connector management guide.

Users can review their own tool calls on the Usage tab once you turn on tool call recording.

Next steps​