Skip to main content

Remote MCP Server

Connect an MCP host to your organization's Glean knowledge graph and the tools your administrator has enabled. The Remote MCP Server is tenant-specific and permission-aware. Each person uses their own Glean access.

note

This is different from the public Docs MCP Server, which gives a coding assistant access to Glean developer documentation. Use the Remote MCP Server for your organization's indexed knowledge and configured tools.

Check that you can connect

Glean enables the OAuth Authorization Server and Remote MCP Server by default for eligible tenants. Administrators can disable MCP or hide the end-user Configurator. Open the Configurator first. If it is unavailable, ask an administrator to confirm that at least one MCP server is enabled and that the Configurator is visible.

1

Open the MCP Configurator

Open the MCP Configurator, choose the server you want to connect, and copy its URL. Selecting a host is optional; do it when you want setup instructions tailored to that application. See the MCP Configurator user guide if the navigation in Glean differs.

2

If the Configurator is missing

If the Configurator is unavailable, ask a Glean administrator to confirm that at least one MCP server is enabled and that the end-user Configurator is visible. That check lives in Set up Glean MCP server.

3

Match the host to its setup path

Check Supported MCP Hosts to see whether your host is user-configurable or organization-managed. One server URL connects any MCP host, including hosts the Configurator does not list. For an unlisted host, use that URL with the host's own MCP setup instructions.

Connect with OAuth

Complete the host's OAuth sign-in flow with your organization's SSO when prompted.

Dynamic Client Registration (DCR) is the usual path for MCP hosts. A tenant can allow any DCR-capable application, restrict registration to approved applications, or turn DCR off. Glean provisions new and previously unconfigured default-on MCP tenants with the Glean-managed list of approved applications; tenants with existing MCP or OAuth configuration keep their settings. If DCR is disabled, your tenant does not allow the host to register, or the host needs scopes DCR does not grant, an administrator can register a static OAuth client. See OAuth authentication for the DCR versus static model.

Use a Glean-issued API token only when the host cannot complete OAuth. Do not assign API Token Creator in bulk as an MCP rollout.

Verify the connection

After the host reports that it is connected, start a new conversation and ask something explicit, such as "Search Glean for our engineering onboarding guide." Confirm that the host shows the Glean server and tools, asks for authorization when required, and returns only content you can access in Glean.

If the server is connected but tools do not load, or a verification request fails, follow Remote MCP troubleshooting. Hosts choose which tools to call, so name the data or action you want when you test.

Install individually or manage centrally