Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To use Docker Desktop’s MCP server integration, install Docker Desktop 4.62 or later, enable the beta Docker MCP Toolkit, create or select a profile, add the required servers from the Catalog, and connect your AI client from the Clients page. Docker’s Gateway then routes requests from the client to the selected servers. If your client is not listed, configure it to launch the Gateway over standard input/output (stdio) with the Docker CLI.

The name in current Docker documentation is Docker MCP Toolkit, not a single monolithic MCP server. The Toolkit manages containerized and remote MCP servers, profiles, authentication, and the Gateway that connects them to applications such as Claude, Cursor, or another MCP-compatible client.

Before you start

  • Install or update Docker Desktop to 4.62 or later. The interface and docker mcp commands described here target that release line and later.
  • Use an AI application that supports MCP, or one that can launch an MCP server through a stdio command.
  • Have credentials ready for any catalog server that requires them. Authentication is configured per server; not every server uses OAuth.
  • Decide whether the servers should be available in a project-specific profile or in the default profile.

The Toolkit is labeled Beta in the current Docker Desktop documentation, so labels, supported clients, and command flags can change between releases.

Set up the Toolkit in Docker Desktop

  1. Enable the feature. Open Docker Desktop, select Settings, choose Beta features, turn on Docker MCP Toolkit, and select Apply.
  2. Create or select a profile. Open MCP Toolkit > Profiles. Select the existing default profile or create a named profile for a project. A profile is the server collection exposed to a client through the Gateway.
  3. Add servers. Open Catalog, choose a server, and add it to the intended profile. A server marked Configuration Required cannot be used until its required fields are completed.
  4. Configure credentials. Open the server’s configuration. If it offers OAuth, select OAuth, authorize in the browser, and return to Docker Desktop. OAuth authorizations are visible under the Toolkit’s OAuth area and can be revoked there. For servers that use tokens, usernames, or other fields, follow that server’s configuration page instead.
  5. Connect your client. Open Clients, locate the AI application, and select Connect. Docker’s supported-client list can change, so a missing application should be treated as unsupported by the current Desktop release rather than forced through an unrelated connector.
  6. Verify both layers. Follow the client-specific verification instructions. For Claude, for example, you can inspect its MCP server list; in any client, send a prompt that invokes a tool from the server you added. A client connection alone proves Gateway connectivity, not that every selected server is configured correctly.

How the Docker MCP architecture works

MCP client

The client is the AI application that requests tools or resources. It does not need to know how each tool is packaged; it communicates with the Gateway using the connection method configured for that client.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MCP server

A server exposes tools or resources. In the Toolkit Catalog, local servers run in Docker containers. Remote services run on the provider’s infrastructure and may require provider-specific authentication.

Profile

A profile is a named collection of configured servers. Selecting a profile determines which servers a Gateway-connected client can access, making separate profiles useful for isolating work projects, credentials, or experiments.

Gateway

The Gateway is the central proxy between the client and the selected servers. It routes each request to the appropriate server and starts a local server container when needed. The client therefore connects to one Gateway instead of maintaining a separate connection definition for every server.

Connect a client that Docker lists

The simplest route is the Clients > Connect button in Docker Desktop. After selecting a profile and connecting, restart or reload the client if its MCP list does not refresh automatically. Then test a specific tool, not merely the presence of a connection. If the tool reports missing credentials, return to the server’s configuration in the profile and complete its required fields.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect Claude Desktop or another named client from the CLI

The CLI reference provides a client command for supported applications:

docker mcp client connect <client> --profile <profile-id>

Use --global when you intentionally want to change system-wide client configuration instead of the current repository or project scope. Client names and available flags depend on the installed Docker Desktop release, so check the command’s help output if a name is rejected.

Use the CLI for repeatable setup

CLI setup is useful when you want a reproducible profile, a scripted workstation bootstrap, or a headless workflow. The documented command sequence is:

  1. Create a profile:
    docker mcp profile create --name <profile-id>
  2. Add a catalog server:
    docker mcp profile server add <profile-id> --server catalog://<catalog-ref>/<server-id>
  3. List the profile’s servers:
    docker mcp profile server ls
  4. Run the Gateway:
    docker mcp gateway run --profile <profile-id>

Omit --profile from the Gateway command to use the default profile. Keep the profile identifier consistent with the one used by your client; otherwise the Gateway can start successfully while exposing the wrong server set.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Manual stdio configuration for an unlisted client

An unlisted MCP client can work if it can launch a local command over stdio. A generic JSON-based configuration commonly has this shape:

{
  "mcpServers": {
    "docker": {
      "command": "docker",
      "args": ["mcp", "gateway", "run", "--profile", "my-project"]
    }
  }
}

Replace my-project with your profile ID. The property names, file location, and whether the client expects an mcpServers object vary by application; use the client’s own configuration format. Claude Desktop, for example, uses its own mcpServers configuration shape. The important values are the docker executable and the argument sequence that starts the Gateway.

Choose local or remote catalog servers

Characteristic Local catalog server Remote service
Where it runs In a Docker container on your machine On the provider’s infrastructure
Offline behavior Docker says local servers work offline after they are downloaded Requires the provider’s service and network access
Operations Docker builds and signs the local catalog servers Availability and implementation are controlled by the provider
Authentication Depends on the server; may use tokens or OAuth Often uses provider credentials or OAuth

These are Toolkit-level distinctions, not a guarantee that every third-party service has identical behavior. Review the selected server’s configuration and permissions before adding it to a profile.

Authentication, permissions, and isolation

Configure only what a server needs

For an OAuth-capable server, add it first, open its configuration, choose OAuth, complete the browser authorization, and return to Docker Desktop. You can revoke an authorization from the OAuth section. Other servers may require a username, personal access token, API key, or a custom endpoint. For example, a Docker Hub MCP server documents username and personal access-token fields rather than assuming OAuth.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand the documented container controls

Control Documented Toolkit behavior What you still need to review
CPU 1 CPU limit for MCP tools Whether a tool’s workload fits that limit
Memory 2 GB limit for MCP tools Large files, indexing jobs, and server-specific requirements
Host files No host filesystem access by default Any explicit mount you approve
Sensitive data Requests to and from tools containing sensitive information, such as secrets, are blocked Credentials, external service access, and the server’s own permissions

These defaults reduce exposure but do not replace a permission review. An explicit mount, a powerful external token, or a remote provider can still grant consequential access.

Verify, update, and operate profiles safely

  • Test a real tool: Ask the client to call one known tool and confirm the expected result.
  • Inspect the active profile: If a tool is missing, check that it was added to the profile named in the client configuration.
  • Separate credentials: Use different profiles for personal, work, and experimental services when access boundaries matter.
  • Keep Desktop current: Beta UI labels and supported-client names can change; recheck the current command reference after an upgrade.
  • Plan for startup cost: A local server may be started on demand by the Gateway, so the first call can take longer than later calls.
  • Account for provider dependency: Remote servers depend on network connectivity and the provider’s service, even when the client and Gateway are local.

Common problems and fixes

Docker MCP Toolkit is missing from Settings

Confirm that Docker Desktop is on the release line that supports the documented Toolkit interface and that you are looking under Settings > Beta features. Restart Docker Desktop after updating or enabling the feature.

The client connects but no tools appear

Check the profile ID in the client configuration, list the profile’s servers, and confirm the server was added rather than merely viewed in the Catalog. Reload the client after changing its MCP configuration.

A server shows “Configuration Required”

Open that server from the profile and complete every required field. If the server uses OAuth, finish the browser flow and verify that the authorization appears in the OAuth area. If it asks for a token or username, do not substitute an OAuth flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Gateway command exits immediately

Run the command directly in a terminal and verify that Docker Desktop is running, the profile exists, and the profile contains a valid server. Remove a manually added profile flag to test the default profile, or specify the intended profile explicitly.

A local server cannot reach a file

Host filesystem access is not provided by default. Review whether the server actually needs a mount and approve only the specific path required by the server’s configuration.

OAuth authorization is stale or belongs to the wrong account

Revoke the authorization in the Toolkit’s OAuth area, then repeat the server’s OAuth setup with the intended account. Check the active profile so the client is not using a similarly named server configured with different credentials.

An unlisted client rejects the JSON

The command may be correct while the schema is wrong for that application. Adapt the client’s required property names and configuration-file location, keeping the executable as docker and the arguments as mcp gateway run --profile <profile-id>.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your goal is simply to capture a webpage for an AI workflow, ScreenshotNeo provides a direct screenshot API and an MCP server for Claude, Cursor, and other MCP clients. One request returns PNG, JPEG, WebP, or PDF without you managing a browser container.

With the API, cookie and consent banners are accepted and removed before capture, along with more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

cURL

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo API documentation for the full option set, including full-page lazy-image loading, CSS-selector element capture, device presets, dark mode, retina scale, PDFs, custom CSS and JavaScript, click actions, waits, request blocking, headers, cookies, geolocation, signed links, asynchronous jobs, bulk capture, caching, and usage reporting. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to AI agents.

Every plan includes all features: 1,000 screenshots per month are free with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FAQ

Frequently Asked Questions

Can one AI client use different Docker MCP profiles?

Yes. Configure separate client entries or launch commands with different profile IDs, then verify which entry is active before invoking a tool.

Do remote catalog servers run inside my Docker Desktop installation?

No. Docker describes remote services as running on provider infrastructure; only local catalog servers are containerized on your machine.

Can I use the Toolkit without granting host-folder access?

Yes. Host filesystem access is off by default. A server only receives a mount when you explicitly select one, although it may still access external services through its configured credentials.

What should I check after upgrading Docker Desktop?

Reconfirm the beta feature is enabled, review the supported-client list, and run the Gateway and client-connect help commands because beta labels and flags can change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.