This sample uses FastMCP 4 and exposes the modern MCP 2026-07-28 HTTP
protocol. Use compatible upstream servers and clients, and test the methods
and capabilities your workload needs. MCP Gateway itself does not translate
legacy protocols or preserve upstream transport sessions. See the
migration guide.
npx, uvx, etc.).With this, you can transform local-only MCP servers into cloud-accessible services that plug directly into your AI workflows.
az acr build -r "mgreg$resourceLabel" -f sample-servers/mcp-proxy/Dockerfile sample-servers/mcp-proxy -t "mgreg$resourceLabel.azurecr.io/mcp-proxy:1.0.0"
mg-identity-<identifier>-workload.
This identity is created by deployment. The MCP server will use the workload identity for upstream resource access.For starting a local MCP server in stdio and proxying the traffic through gateway to it. Set server startup command and arguments in environment variables:
MCP_COMMANDMCP_ARGSSet useWorkloadIdentity to be true if need the server to use the workload identity.
Note: When using a bridged local server, certain system packages may be missing by default. To address this, you can install the required packages within a custom Dockerfile and build your own
mcp-proxyimage.
For proxying another internal mcp server hosted in streamable HTTP. Set the target endpoint in environment variable
MCP_PROXY_URLMCP_PROXY_HEADERS_SECRET_URL as an optional Azure Key Vault secret URLThe referenced secret must contain a JSON object of upstream HTTP headers. Store
credentials only in Key Vault. The gateway stores and returns the secret URL,
but never receives the secret value. Raw MCP_PROXY_HEADERS values are rejected.
The proxy pod must be able to reach that upstream endpoint. The default gateway network policy does not allow arbitrary adapter-to-adapter traffic; add a narrowly scoped rule when intentionally proxying another in-cluster adapter. Do not allow all adapters to reach one another merely to enable a single proxy chain.
Example payloads to send to mcp-gateway using the POST /adapters endpoint to launch a mcp server remotely.
{
"name": "azure-remote",
"imageName": "mcp-proxy",
"imageVersion": "1.0.0",
"environmentVariables": {
"MCP_COMMAND": "npx",
"MCP_ARGS": "-y @azure/mcp@latest server start",
"AZURE_MCP_INCLUDE_PRODUCTION_CREDENTIALS": "true",
"DOTNET_SYSTEM_GLOBALIZATION_INVARIANT": "1"
},
"description": "Bridged Azure local MCP server"
}
{
"name": "foundry-remote",
"imageName": "mcp-proxy",
"imageVersion": "1.0.0",
"environmentVariables": {
"MCP_COMMAND": "uvx",
"MCP_ARGS": "--prerelease=allow --from git+https://github.com/azure-ai-foundry/mcp-foundry.git run-azure-ai-foundry-mcp"
},
"useWorkloadIdentity": true,
"description": "Bridged Azure AI Foundry Local MCP Server"
}
{
"name": "ado-remote",
"imageName": "mcp-proxy",
"imageVersion": "1.0.0",
"environmentVariables": {
"MCP_COMMAND": "npx",
"MCP_ARGS": "-y @azure-devops/mcp contoso",
"ADO_MCP_AZURE_TOKEN_CREDENTIALS": "WorkloadIdentityCredential",
"AZURE_TOKEN_CREDENTIALS": "WorkloadIdentityCredential"
},
"useWorkloadIdentity": true,
"description": "Bridged ADO MCP Local Server"
}
Note: Different MCP servers have different conventions for reading credentials from the environment for setting up
TokenCredentialand connect to upstream resources. You may need to adjust the environment variable names/values per server.
Examples: Some servers expect a general switch likeAZURE_TOKEN_CREDENTIALS=WorkloadIdentityCredentialOthers use service-specific variables (e.g.,ADO_MCP_AZURE_TOKEN_CREDENTIALS)
{
"name": "internal-mcp",
"imageName": "mcp-proxy",
"imageVersion": "1.0.0",
"environmentVariables": {
"MCP_PROXY_URL": "https://internal-mcp-server/mcp"
},
"description": "Proxied Internal MCP Server"
}
Prefer the upstream provider’s OAuth flow when available. For a server that requires a static bearer token, store this JSON in Key Vault:
{"Authorization":"Bearer <token>"}
Grant the adapter workload identity permission to read that secret. Then submit only its URL through the management API:
{
"name": "authenticated-remote",
"imageName": "mcp-proxy",
"imageVersion": "1.0.0",
"environmentVariables": {
"MCP_PROXY_URL": "https://mcp.example.com/mcp",
"MCP_PROXY_HEADERS_SECRET_URL": "https://<vault>.vault.azure.net/secrets/<secret-name>"
},
"useWorkloadIdentity": true,
"description": "Proxied authenticated MCP server"
}
Before running in production
environmentVariables; management GET and LIST responses include those values.MCP_PROXY_HEADERS_SECRET_URL.https:// upstream whenever proxy headers are configured.