Skip to content

Apply policies to an MCP proxy

Once you create an MCP proxy, open it from MCP > MCP Proxies and go to its Policies tab to apply policies.

AI Workspace provides built-in policies that govern how traffic flows through your MCP proxies. A policy applies to the whole proxy by default. Inside an MCP-specific policy you can also define rules per tool or per prompt. Those rules apply the policy at each capability level.

Access control policies

These policies enforce security for MCP proxies.

Policy Description
MCP authentication Applies authentication as defined in the MCP specification.
MCP authorization Applies fine-grained authorization for MCP capabilities and JSON-RPC methods.
MCP access control Allows or denies access to MCP capabilities.

Other policies

Policy Description
MCP rewrite Rewrites the MCP capabilities returned through the proxy. When applied, the proxy returns only the modified capabilities.

You can apply the other standard policies to MCP proxies too. Not every policy supports MCP traffic. Check the policy's entry in the Policy Hub for its supported proxy types and behavior before you attach it.

Policy Hub

The policies in AI Workspace are powered by the Policy Hub, a central registry of the available policies and their versions.

Visit the Policy Hub to explore all available policies, their documentation, and configuration schemas.