Apply policies to an MCP proxy¶
Once you create an MCP proxy, open it from MCP > MCP Proxies and go to its Policies tab to apply policies.
AI Workspace provides built-in policies that govern how traffic flows through your MCP proxies. A policy applies to the whole proxy by default. Inside an MCP-specific policy you can also define rules per tool or per prompt. Those rules apply the policy at each capability level.
Access control policies¶
These policies enforce security for MCP proxies.
| Policy | Description |
|---|---|
| MCP authentication | Applies authentication as defined in the MCP specification. |
| MCP authorization | Applies fine-grained authorization for MCP capabilities and JSON-RPC methods. |
| MCP access control | Allows or denies access to MCP capabilities. |
Other policies¶
| Policy | Description |
|---|---|
| MCP rewrite | Rewrites the MCP capabilities returned through the proxy. When applied, the proxy returns only the modified capabilities. |
You can apply the other standard policies to MCP proxies too. Not every policy supports MCP traffic. Check the policy's entry in the Policy Hub for its supported proxy types and behavior before you attach it.
Policy Hub¶
The policies in AI Workspace are powered by the Policy Hub, a central registry of the available policies and their versions.
Visit the Policy Hub to explore all available policies, their documentation, and configuration schemas.