Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Docker’s MCP Gateway connects an AI client to MCP servers through a profile that controls which servers are available. On Docker Desktop, enable MCP Toolkit, add servers to a profile, then connect and verify your client. If you prefer a terminal workflow—or use a client not listed in Toolkit—you can create a profile with docker mcp commands and launch it over stdio.

The steps and command names below follow Docker’s documentation for Docker Desktop 4.62 and later. Docker labels MCP Toolkit beta, and client setup can vary by application. See Docker’s getting-started guide for the current UI flow.

What the Docker MCP Gateway does

The Gateway is a broker between MCP clients—AI applications that call tools—and MCP servers that provide those tools. Docker describes it as an open-source solution for orchestrating MCP servers. It manages configuration, credentials, access control, routing and server lifecycle: a client sends a tool request to the Gateway, which routes it to the relevant server, starts that server in a Docker container if needed, applies configured restrictions and returns the result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Profiles define which servers are available to a client. This lets you separate tools by project or environment rather than exposing every configured server to every task. With Docker Desktop and MCP Toolkit enabled, the Gateway runs automatically in the background; a manual gateway run command is mainly for advanced setups or clients configured directly. Docker describes container isolation and restrictions on privileges, network access and resource use, but your actual security depends on the server, its permissions, Gateway configuration and client setup. Read Docker’s MCP Gateway overview before deciding which servers and permissions to enable.

Choose a setup path

Path Best fit How the Gateway starts
Docker Desktop MCP Toolkit You want a managed UI and your client is supported in Toolkit. Automatically in the background after Toolkit is enabled.
CLI profile and direct client configuration You want terminal-based profile management, scripting or to configure a client that is not listed. Configure the client to launch docker mcp gateway run --profile <profile-id>, typically over stdio.
Docker Engine without Docker Desktop You run Docker Engine and need the Gateway CLI plugin separately. Install the plugin, then use its CLI. Follow Docker’s current platform and release instructions.

The UI and CLI steps documented here apply to Docker Desktop 4.62 and later; earlier releases may have a different UI or lack some commands. Toolkit is marked beta, so labels and availability can change. For version details, consult Docker’s MCP Toolkit documentation.

Set up the Gateway in Docker Desktop

  1. Enable MCP Toolkit. In Docker Desktop, open Settings > Beta features, enable MCP Toolkit and select Apply.
  2. Open MCP Toolkit and choose a profile. Create a profile for this project or use the existing default profile. Profiles help keep server sets specific to a project or environment.
  3. Add the servers you need. Browse the Catalog and add only the servers required for your task to the chosen profile. If a server shows Configuration Required, complete its required setup before trying to use it.
  4. Connect your AI application. Open the Toolkit’s Clients tab, select your application and follow the displayed connection instructions.
  5. Verify the connection. Follow the client-specific verification instructions shown in Toolkit, then make a small test request that uses a tool from one of the profile’s servers.

Some servers need credentials or other values before they can run. Enter only the configuration that the server requires, and use the server’s own documentation or its Toolkit Catalog configuration view to determine valid keys and values. For OAuth servers, authorize the server in Docker Desktop after adding it. The managed setup sequence is documented in Get started with Docker MCP Toolkit.

Create a profile and add servers with the CLI

Docker’s documented CLI commands are available with Docker Desktop 4.62 and later. This example creates a profile called web-dev, lists a catalog, adds two catalog servers, checks the resulting profile and starts the Gateway:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
docker mcp profile create --name web-dev
docker mcp catalog server ls mcp/docker-mcp-catalog
docker mcp profile server add web-dev 
  --server catalog://mcp/docker-mcp-catalog/github-official 
  --server catalog://mcp/docker-mcp-catalog/playwright
docker mcp profile server ls --filter profile=web-dev
docker mcp gateway run --profile web-dev

The server identifiers in the example are references to catalog entries, not credentials; confirm that the entries and their configuration fit your task. Docker’s CLI guide covers profile and server commands.

Understand server reference formats

The CLI accepts several kinds of server reference. Use the form that matches how the server is distributed:

  • catalog://<catalog-ref>/<server-id> for a catalog entry.
  • docker://<image>:<tag> for a Docker image.
  • https://<url>/v0/servers/<uuid> for a community registry server.
  • file://<path> for a local YAML or JSON definition.

Set a server-specific value

Use profile config with the profile, server ID, key and value required by that server. The key names and accepted values are server-specific; do not assume that a setting for one server applies to another.

docker mcp profile config web-dev --set <server-id>.<key>=<value>

Check the server’s documentation or the Toolkit configuration view for the exact key and expected value. If the server uses OAuth, add it to the profile and authorize it in Docker Desktop.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect a client directly to a profile

For an MCP client that is not listed in Docker Desktop, configure the client to start the Gateway as a stdio process using:

docker mcp gateway run --profile web-dev

Client configuration formats differ: JSON property names and the location of the MCP server entry are determined by the client. Use that application’s instructions for adding a stdio MCP server, set the command to docker, and pass mcp, gateway, run, --profile and the profile ID as its arguments. If Docker’s command-line executable is not on the client’s process path, provide the executable’s full path according to the client’s configuration format. The CLI documentation has client examples and connection guidance at Use MCP Toolkit from the CLI.

In the Desktop-managed flow, Toolkit runs the Gateway automatically; you do not normally need to add a second manual Gateway process to a client already connected through its Clients tab. Avoid configuring both paths for the same client unless you specifically intend to run a separate Gateway connection.

Gateway runtime options and security decisions

The reference for docker mcp gateway run documents stdio as the default transport, with SSE and streaming also available. It lists secrets blocking as enabled by default (--block-secrets=true), Docker Desktop’s secrets API as the default secrets source, and call logging as enabled by default (--log-calls=true). These defaults and flags can vary with installed versions; check docker mcp gateway run --help and the Gateway run reference for the version you use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Transport: stdio is the documented default; SSE and streaming are also listed. Choose the transport supported by the client and deployment you are configuring.
  • Secrets: --block-secrets controls secret blocking, and Docker Desktop’s secrets API is the documented default source. Review what the client and server receive rather than treating the default as a substitute for credential hygiene.
  • Network restrictions: Gateway options can block tools from forbidden network resources. Use such restrictions to narrow access where the workflow permits.
  • Image signatures: The reference includes an option to verify server image signatures. Confirm the behavior and available signature configuration in the installed version’s help.
  • Resource limits: Per-server CPU and memory limits are available so a server can be constrained rather than left unrestricted.
  • Dry run and static mode: The reference lists --dry-run and static mode for specific operational workflows; consult the reference before using them because their effects depend on the invocation and version.
  • Call logging: With --log-calls=true as the documented default, consider what tool activity may be recorded and whether that suits your environment.

Container isolation is a useful layer, not a blanket security guarantee. Select trusted server sources, limit the profile to necessary tools, review credentials and network permissions, and verify the behavior of the client and Gateway flags you actually deploy.

Install the Gateway CLI plugin without Docker Desktop

For Docker Engine environments without Docker Desktop, Docker documents a separate CLI-plugin installation route. Download the latest Gateway binary from its GitHub releases and place it in the Docker CLI plugins directory:

  • Linux and macOS: ~/.docker/cli-plugins/docker-mcp
  • Windows: %USERPROFILE%.dockercli-plugins

On Linux or macOS, make the binary executable and check that Docker recognizes it:

chmod +x ~/.docker/cli-plugins/docker-mcp
docker mcp --help

Release assets and platform instructions can change, so confirm the current release and installation details in Docker’s Gateway documentation before installing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common setup failures

  • docker mcp is unavailable. Check the Docker Desktop version against the documented 4.62-and-later requirement. For Docker Engine without Desktop, verify that the plugin binary is in the correct CLI plugin directory and, on Linux or macOS, is executable.
  • The Toolkit tab or controls do not match the steps. The UI can differ in earlier versions, and Toolkit is beta. Check your Docker Desktop version and current Toolkit documentation; enable Toolkit under Settings > Beta features if it is not enabled.
  • A server cannot start or use a tool. Check that it was added to the profile you are using, that any Configuration Required fields are complete, and that OAuth authorization has been finished where applicable. Confirm the server’s own required values.
  • The profile is empty or the wrong tools appear. List its servers with docker mcp profile server ls --filter profile=<profile-id>. Add the needed server to that profile, then ensure the client launches or connects to the same profile ID.
  • An unlisted client fails to connect. Confirm that the client is configured for stdio and launches docker mcp gateway run --profile <profile-id> with the profile ID as a separate argument. Follow the client’s own MCP configuration format and ensure its process can find the Docker executable.
  • Credentials or permissions are missing. Check the server-specific configuration keys and values, then authorize OAuth servers in Docker Desktop if required. Do not substitute guessed configuration names.
  • A command or flag is rejected. Run docker mcp --help or docker mcp gateway run --help and compare with the version-specific reference. Docker says earlier Desktop versions may not support every documented CLI command.

Or skip the browser setup

If your task is taking website screenshots rather than wiring browser automation tools into an MCP profile, ScreenshotNeo offers a direct screenshot API and an MCP server. One GET request returns a PNG, JPEG, WebP or PDF. The API accepts or removes cookie and consent banners, newsletter popups and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server provides take_screenshot, get_page_info and capture_pdf for Claude, Cursor and other MCP clients. See the ScreenshotNeo API documentation for options and response details.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

There are 1,000 screenshots per month on the free plan with no card required; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo’s free plan.

Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Frequently Asked Questions

Does Docker Desktop need to stay open for MCP Toolkit?

Docker’s documentation describes the Gateway as running automatically in the background when MCP Toolkit is enabled in Docker Desktop.

Can I use a local MCP server definition?

Yes. The documented CLI reference format for a local YAML or JSON server definition is file://<path>.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does every Docker MCP Gateway setup use stdio?

No. The Gateway run reference lists stdio as the default and also documents SSE and streaming transports.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.