MCP solved the hard part of tool use: a common protocol so any agent can call any tool server. The operational part is what it did not solve. Every agent keeps its own MCP configuration, every server's credentials get copied into every agent, and when a server needs OAuth, each client runs its own consent flow.
Prism's MCP gateway collapses that into one endpoint. You configure a server once, in Prism. Every agent reaches it from a single URL with a single token, and Prism holds the credentials and brokers the OAuth.
The shape of the problem
Without a gateway With the Prism gateway
───────────────── ─────────────────────
Claude Code ─┬─ server A Claude Code ─┐
├─ server B │
└─ server C Codex ───────┤ ┌──────────────┐
Codex ───────┬─ server A ├──▶│ /mcp │──▶ A · B · C · D
└─ server D Zed ─────────┤ │ one token │
Zed ─────────┴─ server B Cursor ──────┘ │ broker OAuth │
└──────────────┘Three things get better immediately. Credentials exist in one place instead of one place per agent. Adding a server is one edit instead of one per client. And access becomes an explicit allowlist per agent rather than an accident of which config file somebody edited.
Endpoints
POST http://127.0.0.1:11434/mcp Authorization: Bearer prism Content-Type: application/json # One agent's allowlist instead of everything POST http://127.0.0.1:11434/mcp/claude-code # Health of every server, plus the agent bindings map GET http://127.0.0.1:11434/mcp/status
Tool names arrive namespaced as mcp__<server>__<tool>, so two servers that both expose search stay distinguishable and a call routes unambiguously. Prism advertises that convention in its own initialize /server/discover response, and rejects an unnamespaced tools/call with an error telling the agent to use the names from tools/list.
Setting it up
Add a server
Choose an auth mode
none for open servers, static for a pasted token or header, or oauth to let Prism run the whole OAuth flow for you.Authorise it, if needed
config.json with mode 0600 and refreshes them automatically.Grant agents access
Brokered OAuth is the interesting part
OAuth-based MCP servers are the reason most people give up on sharing MCP configuration. Each client implements its own registration and consent flow, so the same server gets authorised five times and five refresh tokens exist for one account.
Prism does it once. It discovers the server's authorization server, registers a client, runs the consent flow in your browser, and keeps the token. A second MCP server on the same authorization server reuses the registration instead of registering again.
| Registration mode | How the client id is obtained |
|---|---|
| dcr | Dynamic client registration (RFC 7591) — used when the server supports it. |
| preregistered | A client id you already have, entered manually. |
| cimd | Client ID Metadata Document — off by default; needs an HTTPS document you host. |
With auto_connect on — the default — the first agent call to a server that is not yet authorised opens the sign-in window by itself, and the call is retried once you approve. Turn it off if you would rather authorise everything up front.
Where agents get their entry written
Prism knows where each of the 14 supported agents keeps its MCP servers, and the shapes differ more than you would expect:
JSON under mcpServers
Claude Code in ~/.claude.json, Factory Droid in ~/.factory/mcp.json, Pi, OMP, Kimi Code and Prime Agent in their own files.
Provider-shaped or nested keys
OpenCode uses mcp with type: "remote"; ZCode uses mcp.servers; Zed uses context_servers.
TOML and YAML
Codex and Grok Build are TOML, so they get dedicated writers rather than the JSON path that handles most agents.
One file, two regions
Hermes keeps providers and MCP servers in one YAML file, so Prism maintains two independently marked regions and one can be removed without touching the other.
Authorization: Bearer prism— never an upstream key. Removing access deletes only Prism's own entry, leaving servers you configured by hand untouched.The marketplace
The official registry is seeded, and Prism syncs its catalog locally rather than querying per keystroke, so search stays instant and works offline once synced. Any registry that speaks the same API shape can be added as another source, which turns a private or company catalog into a drop-in addition rather than a separate client.
Installs take one of three forms: a package-manager entry such as npx or uvx; an .mcpb bundle, which Prism downloads and only unpacks after its published SHA-256 matches; or a git import, pointed at a repository containing an mcp.json, where every declared server is added at once.
Operational limits worth knowing
Idle stdio reaping
A local server process is shut down after 300 idle seconds and restarted on the next call. An idle state is normal, not a fault.
Timeouts that protect you from one slow server
Tool listing has a 20-second budget and a 30-second cache; a tool call gets 10 minutes. A dead process is restarted once before the failure is reported.
Bounded request size
Inbound JSON-RPC messages are capped at 8 MB, so a malformed client cannot exhaust memory.
Verify a server is actually reachable
curl http://127.0.0.1:11434/mcp/status -H "Authorization: Bearer prism"
# { "statuses": [ { "id": "weather", "name": "Weather", "transport": "stdio",
# "auth_mode": "none", "enabled": true, "state": "ready",
# "tool_count": 3, "authorized": true } ],
# "agents": [ { "agent": "claude-code", "servers": ["weather"] } ] }States are ready, idle, needs_auth, runtime_missing, error and disabled. Those two middle states cover almost every "my tools disappeared" report: one means the credential needs attention, the other means the command for a stdio server was not found.
When not to use it
If you use exactly one agent and exactly one MCP server, a direct entry in that agent's config is simpler and has one less process in the path. The gateway pays for itself as soon as there are two agents, two servers, or any server that needs OAuth.