From 69fc2d83dc44cef04f52377f9c8bfdc4bbf160ad Mon Sep 17 00:00:00 2001 From: Kabilan Sarathi Date: Fri, 18 Sep 2026 18:25:09 +0530 Subject: [PATCH 1/5] W-24154390-Kong-MCP-doc-update-KS --- .../exp-scanners-add-from-providers.adoc | 54 ++++++++++++++++++- .../exp-scanners-prerequisites-reference.adoc | 13 ++++- 2 files changed, 64 insertions(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 31ab8b1b1..455468d85 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -108,8 +108,29 @@ Microsoft Copilot Studio scanners support two authentication schemes. Create, au The OAuth (Authorization Code) flow opens a Microsoft sign-in popup. If your browser blocks popups, authorization can't complete and scanner setup stays in the authorizing state. ==== -[[kong-gateway-scanner-openapi-specifications]] -== Kong Gateway Scanner OpenAPI Specifications +[[kong-gateway-scanner]] +== Kong Gateway Scanner + +The Kong Gateway scanner connects to a Kong control plane and discovers services on one of two platforms that you select during setup: + +* *Kong Gateway (APIs)*: Discovers, imports, and syncs APIs from Kong Gateway into the *APIs* catalog. +* *Kong Gateway (MCP)*: Discovers, imports, and syncs MCP servers from Kong Gateway into the *MCP Servers* catalog. + +Both platforms use the same connection credentials and setup steps. Only the platform you select differs. + +=== Add a Kong Gateway Scanner + +. From *Platform* > *Providers*, select *Kong*. +. In *Connect to Provider*, under *Platform*, select the platform to scan: +* *Kong Gateway (APIs)* to discover APIs. +* *Kong Gateway (MCP)* to discover MCP servers. +. Enter connection values: +* *Kong Gateway Region*: Select the Kong Gateway region. +* *Personal Access Token*: Enter the personal access token. +. Click *Test Connection* and confirm the connection succeeds. +. Click *Continue*, then name, schedule, and save the scanner to complete setup. + +=== OpenAPI Specifications To discover accurate, typed API definitions from Kong Gateway, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). The scanner reads the OAS from the linked Catalog API to build a complete, typed service definition. @@ -128,6 +149,35 @@ For more information, see the https://developer.konghq.com/api-catalog/[Kong API If a Kong Gateway service isn't linked to a Catalog API with an attached OAS, only the first route per path is discovered. For example, if the `/items` path has both `GET` and `POST` routes, only one of those routes appears in the discovered definition. Link the service to a Catalog API with an attached OAS to discover all routes and methods for each path. ==== +=== Protocol to Asset Type Mapping + +When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns an asset type to each discovered service based on the service's Kong protocol and plugins. + +[%header,cols="1,1,1"] +|=== +|Protocol |Plugin |Asset type + +|`grpc` / `grpcs` +|— +|gRPC + +|`http` / `https` +|`graphql-*` +|GraphQL + +|`http` / `https` +|No matching plugin +|REST +|=== + +The scanner currently detects gRPC and GraphQL protocols only. + +NOTE: Services that use other protocols or plugins, such as WebSocket or Simple Object Access Protocol (SOAP), are registered as asset type REST for now. MuleSoft plans to support these protocols in a future release. + +=== Rescanning Behavior + +On the *Kong Gateway (APIs)* platform, the scanner assigns an asset type to a service the first time it discovers that service. Later scans don't update that asset type, even if the service's protocol changes in Kong Gateway. To change an asset's type, remove the asset, and let the scanner import it again. + == Scanner Configuration Overview Regardless of entry point, adding a scanner establishes trust and scope. You specify which provider platform to reach, how the system authenticates, and how you validate connectivity. You also name and schedule the scanner—or configure another trigger—so discovery runs on the cadence your team expects. Saving the configuration activates the scanner for the catalogs and features your administrator enabled. diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index a4b161d04..222926037 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -204,7 +204,7 @@ a| *Write scope (policy apply):* Admin API write permission required to apply, enable, disable, or remove policy in target environments -*Setup:* To discover accurate, typed API definitions, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner-openapi-specifications[]. +*Setup:* To discover accurate, typed API definitions, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner]. | Akamai Security | API Security @@ -239,6 +239,17 @@ a| *Role:* API Management Service Reader +| Kong Gateway MCP Server +| MCP +a| +*Credentials:* Personal access token (PAT); Kong Gateway region + +*Role:* Kong Control Plane Viewer + +* *Read scope:* Admin API read permission required to discover MCP servers in target environments + +*Setup:* Link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). A linked OAS produces higher-quality MCP servers bridged from discovered services. For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner]. + | Snowflake MCP Server | MCP a| From 4db35858f3f5776043a4626e1505887407a201f3 Mon Sep 17 00:00:00 2001 From: Kabilan-s-cx Date: Mon, 21 Sep 2026 11:53:29 +0530 Subject: [PATCH 2/5] Apply suggestion from @JennyHajee Co-authored-by: Jenny Hajee <94015849+JennyHajee@users.noreply.github.com> --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 455468d85..9f25b8ff6 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -151,7 +151,7 @@ If a Kong Gateway service isn't linked to a Catalog API with an attached OAS, on === Protocol to Asset Type Mapping -When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns an asset type to each discovered service based on the service's Kong protocol and plugins. +When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns an service type to each discovered service based on the service's Kong protocol and plugins. [%header,cols="1,1,1"] |=== From 84694707fbdf08e6ac3c8b9ffedd733155157c1b Mon Sep 17 00:00:00 2001 From: Kabilan-s-cx Date: Mon, 21 Sep 2026 11:53:40 +0530 Subject: [PATCH 3/5] Apply suggestion from @JennyHajee Co-authored-by: Jenny Hajee <94015849+JennyHajee@users.noreply.github.com> --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 9f25b8ff6..9615191a8 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -172,7 +172,7 @@ When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns an se The scanner currently detects gRPC and GraphQL protocols only. -NOTE: Services that use other protocols or plugins, such as WebSocket or Simple Object Access Protocol (SOAP), are registered as asset type REST for now. MuleSoft plans to support these protocols in a future release. +NOTE: Services that use other protocols or plugins, such as WebSocket or Simple Object Access Protocol (SOAP), are registered as service type REST for now. === Rescanning Behavior From 5e6af0e865311dce3880e14a07a1992c666029ed Mon Sep 17 00:00:00 2001 From: Kabilan-s-cx Date: Mon, 21 Sep 2026 11:54:02 +0530 Subject: [PATCH 4/5] Update exp-scanners-add-from-providers.adoc --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 9615191a8..521c6c27a 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -151,7 +151,7 @@ If a Kong Gateway service isn't linked to a Catalog API with an attached OAS, on === Protocol to Asset Type Mapping -When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns an service type to each discovered service based on the service's Kong protocol and plugins. +When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns a service type to each discovered service based on the service's Kong protocol and plugins. [%header,cols="1,1,1"] |=== From 72cdfa9914079a7ba5953fb95981678dcc3e5e2f Mon Sep 17 00:00:00 2001 From: Kabilan Sarathi Date: Tue, 22 Sep 2026 15:49:41 +0530 Subject: [PATCH 5/5] fixed comments --- .../ROOT/pages/exp-scanners-prerequisites-reference.adoc | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index 222926037..a47104e72 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -248,7 +248,12 @@ a| * *Read scope:* Admin API read permission required to discover MCP servers in target environments -*Setup:* Link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). A linked OAS produces higher-quality MCP servers bridged from discovered services. For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner]. +*Setup:* Create the MCP servers for the scanner to discover in one of two ways: + +* In the Kong control plane, add a gateway service and attach an MCP-related plugin to it. +* In Kong Catalog, open *MCP Servers* and create a new MCP server. + +The MCP servers reflect only the routes present in the control plane gateway services. For route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner]. | Snowflake MCP Server | MCP