Skip to content
Platform Status

Secure

Shadow MCP

The Shadow MCP page inventories MCP servers discovered in agent traffic that aren’t managed by the platform — servers members connected on their own. Open it from Secure > Shadow MCP in the dashboard.

Shadow MCP detection depends on an active shadow MCP policy; a status banner on the page shows whether one is scanning and links to Risk Policies if not.

Viewing this page requires the org:admin scope. Access is included in the default Admin role but not the Member role.

The inventory table lists each discovered server with its status and allow decision. Statuses distinguish servers that are pending review from those that have been allowed or blocked.

Opening a server shows:

  • The server’s status and any allow rules that apply
  • A Top users table — who uses the server, how often, and when it was last called
  • An Add Allow Rule action to sanction the server for continued use

Use the detail view to decide whether a discovered server should be sanctioned (and ideally brought under management as a proper source) or blocked by policy.