Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 52 additions & 2 deletions modules/ROOT/pages/exp-scanners-add-from-providers.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -108,8 +108,29 @@ Microsoft Copilot Studio scanners support two authentication schemes. Create, au
The OAuth (Authorization Code) flow opens a Microsoft sign-in popup. If your browser blocks popups, authorization can't complete and scanner setup stays in the authorizing state.
====

[[kong-gateway-scanner-openapi-specifications]]
== Kong Gateway Scanner OpenAPI Specifications
[[kong-gateway-scanner]]
== Kong Gateway Scanner

The Kong Gateway scanner connects to a Kong control plane and discovers services on one of two platforms that you select during setup:

* *Kong Gateway (APIs)*: Discovers, imports, and syncs APIs from Kong Gateway into the *APIs* catalog.
* *Kong Gateway (MCP)*: Discovers, imports, and syncs MCP servers from Kong Gateway into the *MCP Servers* catalog.

Both platforms use the same connection credentials and setup steps. Only the platform you select differs.

=== Add a Kong Gateway Scanner

. From *Platform* > *Providers*, select *Kong*.
. In *Connect to Provider*, under *Platform*, select the platform to scan:
* *Kong Gateway (APIs)* to discover APIs.
* *Kong Gateway (MCP)* to discover MCP servers.
. Enter connection values:
* *Kong Gateway Region*: Select the Kong Gateway region.
* *Personal Access Token*: Enter the personal access token.
. Click *Test Connection* and confirm the connection succeeds.
. Click *Continue*, then name, schedule, and save the scanner to complete setup.

=== OpenAPI Specifications

To discover accurate, typed API definitions from Kong Gateway, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). The scanner reads the OAS from the linked Catalog API to build a complete, typed service definition.

Expand All @@ -128,6 +149,35 @@ For more information, see the https://developer.konghq.com/api-catalog/[Kong API
If a Kong Gateway service isn't linked to a Catalog API with an attached OAS, only the first route per path is discovered. For example, if the `/items` path has both `GET` and `POST` routes, only one of those routes appears in the discovered definition. Link the service to a Catalog API with an attached OAS to discover all routes and methods for each path.
====

=== Protocol to Asset Type Mapping

When you scan with the *Kong Gateway (APIs)* platform, the scanner assigns a service type to each discovered service based on the service's Kong protocol and plugins.

[%header,cols="1,1,1"]
|===
|Protocol |Plugin |Asset type

|`grpc` / `grpcs`
|—
|gRPC

|`http` / `https`
|`graphql-*`
|GraphQL

|`http` / `https`
|No matching plugin
|REST
|===

The scanner currently detects gRPC and GraphQL protocols only.

NOTE: Services that use other protocols or plugins, such as WebSocket or Simple Object Access Protocol (SOAP), are registered as service type REST for now.

=== Rescanning Behavior

On the *Kong Gateway (APIs)* platform, the scanner assigns an asset type to a service the first time it discovers that service. Later scans don't update that asset type, even if the service's protocol changes in Kong Gateway. To change an asset's type, remove the asset, and let the scanner import it again.

== Scanner Configuration Overview

Regardless of entry point, adding a scanner establishes trust and scope. You specify which provider platform to reach, how the system authenticates, and how you validate connectivity. You also name and schedule the scanner—or configure another trigger—so discovery runs on the cadence your team expects. Saving the configuration activates the scanner for the catalogs and features your administrator enabled.
Expand Down
18 changes: 17 additions & 1 deletion modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -204,7 +204,7 @@ a|

*Write scope (policy apply):* Admin API write permission required to apply, enable, disable, or remove policy in target environments

*Setup:* To discover accurate, typed API definitions, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner-openapi-specifications[].
*Setup:* To discover accurate, typed API definitions, link each Kong Gateway service to a Catalog API that has an attached OpenAPI Specification (OAS). For the required workflow and route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner].

| Akamai Security
| API Security
Expand Down Expand Up @@ -239,6 +239,22 @@ a|

*Role:* API Management Service Reader

| Kong Gateway MCP Server
| MCP
a|
*Credentials:* Personal access token (PAT); Kong Gateway region

*Role:* Kong Control Plane Viewer

* *Read scope:* Admin API read permission required to discover MCP servers in target environments

*Setup:* Create the MCP servers for the scanner to discover in one of two ways:

* In the Kong control plane, add a gateway service and attach an MCP-related plugin to it.
* In Kong Catalog, open *MCP Servers* and create a new MCP server.

The MCP servers reflect only the routes present in the control plane gateway services. For route-discovery limitations, see xref:exp-scanners-add-from-providers.adoc#kong-gateway-scanner[Kong Gateway Scanner].

| Snowflake MCP Server
| MCP
a|
Expand Down