Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Docker MCP is Docker’s ecosystem for finding, configuring and running Model Context Protocol (MCP) servers. It combines a curated Catalog, the Docker Desktop MCP Toolkit, project-specific profiles and the MCP Gateway. Together, these components let an MCP-compatible AI application call tools hosted in isolated containers instead of connecting to every service directly.

MCP itself is an open standard: an AI application acts as a client, while an MCP server exposes tools or data to that client. Docker supplies the catalog, management layer and routing infrastructure around those servers.

What MCP means

Model Context Protocol standardizes how AI applications connect to external tools and data. An MCP client is normally built into an AI application such as an MCP-compatible coding assistant. An MCP server publishes callable tools or resources, such as access to a service, database or development workflow. The protocol defines the conversation between them; it does not make every server trustworthy or remove the need to review permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Without a management layer, users must discover servers, install them, provide credentials and configure each AI client separately. Docker MCP addresses those operational tasks with several components that have different jobs.

Docker MCP’s four main components

Docker MCP Catalog

The Catalog is the library of available MCP server definitions and container images. Docker’s current documentation reports 300+ verified servers. “Verified” describes Docker’s catalog process, not a guarantee that a server, its dependencies or its returned content is harmless.

The Catalog is an availability list, not the set of servers currently enabled for your project. That distinction matters when auditing which tools an AI client can actually call.

Docker Desktop MCP Toolkit

The Toolkit is the management interface integrated into Docker Desktop. It lets you discover catalog entries, add and configure servers, group them into profiles and connect MCP clients. Docker currently labels the Toolkit Beta; the documented interface applies to Docker Desktop 4.62 and later. Earlier Desktop releases can present a different interface.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Profiles

A profile is a named collection of servers for a project, team or environment. You might create separate profiles for development, customer support and production, enabling only the tools appropriate to each workflow. The Catalog is the library; a profile is the selected, organized set made available to a client.

MCP Gateway

The Gateway is Docker’s open-source proxy and orchestrator between MCP clients and servers. It routes tool requests, handles configuration and credentials, manages server lifecycles and applies access controls. When the Toolkit is enabled in Docker Desktop, the Gateway runs in the background. Users running Docker Engine without Docker Desktop can install the Gateway separately.

How a Docker MCP request works

  1. Choose servers. Find suitable entries in the Catalog.
  2. Add and configure them. Put the selected servers in a Toolkit profile and supply the required service settings or authorization.
  3. Connect the client. Configure an MCP-compatible AI application to use the profile through the Gateway.
  4. Call a tool. The AI application sends a request to the Gateway; the Gateway routes it to the appropriate server and returns the response.

Gateway-managed servers run in containers. Docker documents restricted privileges, network access and resource usage for these containers, so a server is not automatically given unrestricted access to the host.

Catalog versus profile: the distinction developers need

Concept What it represents When you use it
Catalog The collection of available server definitions and images When discovering or evaluating possible tools
Profile A named selection of configured servers When defining the tools available to a particular project or environment

Adding a server to a profile does not mean every other profile or client can use it. Conversely, a server appearing in the Catalog is not necessarily running on your machine.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Toolkit versus Gateway

Component Primary role Typical environment
Toolkit Discover, add, configure and organize servers; connect clients Docker Desktop, currently Beta
Gateway Proxy requests, route calls, manage lifecycle, credentials and access control Background service with Toolkit, or separately installed for Docker Engine

The Toolkit is the user-facing management surface. The Gateway is the runtime path through which client requests reach servers. They complement rather than replace one another.

Docker Desktop and Docker Engine setups

Docker Desktop

Desktop users get the integrated Toolkit experience. After selecting and configuring servers in a profile, the Gateway operates in the background and presents that profile to the connected MCP client.

Docker Engine without Desktop

Engine users can install the open-source Gateway separately and build their own client and server configuration around it. This is a different setup path: there is no assumption that the Desktop Toolkit interface is present. Keep the Desktop documentation’s version-specific UI instructions separate from Engine deployment instructions.

Authentication and credentials

The Toolkit documents OAuth support for some services, including browser-based authorization and credential management. Docker’s FAQ says credentials are stored in the Docker Desktop virtual machine starting with Docker Desktop 4.43.0. Removing a server does not automatically remove stored credentials; remove or revoke those credentials separately when they are no longer needed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Grant only the scopes a server requires.
  • Use separate profiles and credentials for development and production.
  • When decommissioning a server, remove its saved credentials or revoke the upstream authorization.
  • Review which profile is connected before allowing an AI client to perform an action.

What Docker’s security controls do—and do not do

Build-time provenance

Docker documents digital signatures, attestations and software bills of materials for Docker-built catalog images. Most catalog servers are built by Docker; selected third-party servers are built in ephemeral environments and checked for initialization, functionality and whether their tools can be listed.

Runtime boundaries

The Toolkit guide describes a one-CPU limit, a two-GB memory limit, no host-filesystem access by default and interception of requests containing sensitive information. The Gateway security model says images in Docker Hub’s mcp/ namespace have signature verification enabled by default and must be referenced by digest when verification is enabled.

Important limitations

Docker explicitly describes these measures as best effort, not exhaustive. Isolation and provenance can reduce exposure, but they do not prove that a server is benign. The Gateway security model also does not claim to stop prompt injection or malicious content returned by a tool, README, remote service or upstream API unless that content bypasses a documented Gateway boundary. Treat server permissions, upstream accounts and returned instructions as security decisions that still require review.

“Docker’s security measures currently represent a best-effort approach. While Docker implements automated testing, scanning, and metadata extraction for each server in the catalog, these security measures are not yet exhaustive.” — Docker Docs, “MCP Toolkit FAQs”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to choose a profile design

Separate by project

Create one profile per codebase or customer environment when each requires a different set of tools or credentials. This makes the client’s effective tool list easier to inspect.

Separate by risk

Keep read-only research tools apart from tools that can modify tickets, files or production systems. A smaller profile limits the consequences of an incorrect AI decision.

Separate by lifecycle

Use a disposable profile for experiments and a controlled profile for recurring work. Remove unused servers and revoke credentials rather than assuming deletion handled both.

Common problems and fixes

The client cannot see a server

Check that the server was added to the active profile, that the client is connected through the Gateway and that the Toolkit and Docker Desktop versions match the documented interface. A Catalog listing alone does not make a server available.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authorization keeps failing

Repeat the documented OAuth flow, verify the upstream account and scopes, and check whether an old credential remains in the Docker Desktop VM. Removing and re-adding a server does not necessarily delete that credential; revoke it separately.

A server uses too many resources

Review the documented one-CPU and two-GB memory runtime limits. Reduce the number of simultaneously enabled servers, split tools across profiles and investigate the server’s own workload.

Image verification fails

For Gateway verification, confirm that the image is in the expected mcp/ namespace and is referenced by digest as required by the security model. Do not disable verification simply to bypass an unexplained failure; investigate the image provenance instead.

A tool returns suspicious instructions

Stop and inspect the server, README, remote service and upstream response. Container isolation does not guarantee protection from prompt injection or malicious tool output. Do not grant additional permissions merely because the response requests them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changed since launch?

Docker’s May 5, 2025 launch announcement described a beta Catalog with 100+ servers. Current documentation reports 300+ servers. These figures describe different points in time, not conflicting measurements; use the current documentation for present-day coverage. The Toolkit remains labeled Beta, and the Gateway’s open-source project should not be confused with the Gateway feature in Docker AI Governance, which Docker describes as invite-only.

Using an MCP server for website screenshots

If your AI workflow needs website images, ScreenshotNeo is a website screenshot API and MCP server. Its MCP tools—take_screenshot, get_page_info and capture_pdf—can be used by Claude, Cursor or another MCP client. It removes cookie banners, newsletter popups and chat widgets before capture, and only clean shots are billed; bot checks, blank pages, timeouts, failed loads and cache hits are not billed.

ScreenshotNeo supports PNG, JPEG, WebP and PDF output, with options including full-page lazy-image loading, CSS-selector element capture, device presets, custom headers and cookies, JavaScript, waits, request blocking, geolocation, signed links, asynchronous webhooks and bulk capture. Plans include 1,000 free shots per month without a card; paid plans start at $5 for 3,000 shots. See the ScreenshotNeo documentation for configuration details.

Or skip the browser setup

Call the API directly:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cookie banners, popups and chat widgets are removed before the shot; bot checks, blank pages and failed loads are never billed. Its MCP server lets AI agents take screenshots, and 1,000 screenshots a month are free with no card. Create a free ScreenshotNeo account.

FAQ

Is Docker MCP one MCP server?

No. It is a collection of catalog, management, profile and gateway components used to run many MCP servers.

Is the Docker MCP Toolkit stable?

Docker currently labels it Beta, and its documented interface applies to Docker Desktop 4.62 and later.

Does a verified catalog server guarantee safety?

No. Docker describes verification and scanning as best effort and not exhaustive; review permissions and returned content yourself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I use Docker MCP without Docker Desktop?

Yes. Docker Engine users can install the open-source MCP Gateway separately, but they do not get the integrated Desktop Toolkit interface.

The Bottom Line

Docker MCP is best understood as a managed path from an AI client to containerized MCP servers: the Catalog supplies choices, profiles define what a project can use, the Toolkit manages those choices and the Gateway routes requests. Its isolation and provenance controls are useful boundaries, not a substitute for permission review.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.