Skip to main content
Applications are for things your team built. The Portal is for people. Every gateway has one. A person opens it, signs in with their NeuralTrust login, and sees the catalogue: what they can install, what they already have, and the state of their own account on each server. Everything they install becomes available to their agents through one fixed MCP URL — the same catalogue, reached by a client instead of a browser, with three tools to search, install and uninstall. Neither governs applications and applications do not govern it. An application’s surface is what an admin bound; a person’s Portal is what they installed, bounded by their Access level.

Installing

Installing a catalogue server creates or reuses one registry entry per catalogue code on the gateway. What is per person lives elsewhere: their account on a forwarded-auth server, vaulted under their identity, and any per-user setup values a server’s URL is built from. An install answer is a state, not a success flag: The person’s Portal shows the same states — Installed, Connect, Reconnect needed, Pending, Needs admin setup — and under My Access what they hold, with the state of their own account on each.

Open or curated

A gateway’s default access decides what the Portal offers everyone who has no level of their own: A level set on a person or a group overrides the default. The effective level is evaluated on every request, so a change lands immediately. Curated is the setting most organisations end at. It is not a refusal of everything else — it turns “I need this” into a request with a reason attached, decided by an admin, and approving a group instead of a person is how the same request stops arriving.

Reconnecting

A connection is reported as connected only while its credential can still be redeemed. When a provider stops honouring the refresh, the person sees Reconnect needed and the server contributes no tools until they sign in again. The gateway never replays a refresh token a provider already rejected.

Instances

A server that can be connected more than once — two Snowflake schemas, two API keys — holds instances, added by admins from the registry. When several exist the Portal asks which one to install or uninstall, and each holds its own set of per-user accounts.

Where it is

The Portal’s MCP URL is under the gateway’s settings, next to the LLM and MCP gateway URLs. Employees without console access reach the Portal from the platform; admins can preview it as any user from Access.