Feedback: Restrict access to MCP servers (beta)

Share your feedback

We've shipped Restrict access to MCP servers (beta), available on Premium and Ultimate for GitLab.com, self-managed, GitLab Dedicated, and GitLab Dedicated for Government.

This feature lets administrators control which external MCP (Model Context Protocol) servers and tools AI agents can use across your organization. You can:

  • Block or allow an entire external MCP server.
  • Allow or deny individual tools on an MCP server.

These controls apply consistently wherever AI agents run — Agentic Chat, Flows, and IDE and CLI environments — giving you a single, governed place to manage the risk posture of external integrations.

📖 Documentation


We'd love to hear from you

Please share your experience with this feature:

  • Did the controls work as expected across surfaces (chat, flows, IDE/CLI)?
  • Was the admin UI for allowing/blocking servers and tools intuitive?
  • What use cases are you trying to cover that aren't yet supported?
  • Any bugs or unexpected behavior?

Leave a comment below or use the 👍 / 👎 reactions to indicate whether this feature meets your needs.


This is a beta feature. Your feedback directly shapes the roadmap.

Edited by Nate Rosandich