To use Docker Desktop’s MCP server integration, install Docker Desktop 4.62 or later, enable the beta Docker MCP Toolkit, create or select a profile, add the required servers from the Catalog, and connect your AI client from the Clients page. Docker’s Gateway then routes requests from the client to the selected servers. If your client is not listed, configure it to launch the Gateway over standard input/output (stdio) with the Docker CLI.
The name in current Docker documentation is Docker MCP Toolkit, not a single monolithic MCP server. The Toolkit manages containerized and remote MCP servers, profiles, authentication, and the Gateway that connects them to applications such as Claude, Cursor, or another MCP-compatible client.
Before you start
- Install or update Docker Desktop to 4.62 or later. The interface and
docker mcpcommands described here target that release line and later. - Use an AI application that supports MCP, or one that can launch an MCP server through a stdio command.
- Have credentials ready for any catalog server that requires them. Authentication is configured per server; not every server uses OAuth.
- Decide whether the servers should be available in a project-specific profile or in the default profile.
The Toolkit is labeled Beta in the current Docker Desktop documentation, so labels, supported clients, and command flags can change between releases.
Set up the Toolkit in Docker Desktop
- Enable the feature. Open Docker Desktop, select Settings, choose Beta features, turn on Docker MCP Toolkit, and select Apply.
- Create or select a profile. Open MCP Toolkit > Profiles. Select the existing
defaultprofile or create a named profile for a project. A profile is the server collection exposed to a client through the Gateway. - Add servers. Open Catalog, choose a server, and add it to the intended profile. A server marked Configuration Required cannot be used until its required fields are completed.
- Configure credentials. Open the server’s configuration. If it offers OAuth, select OAuth, authorize in the browser, and return to Docker Desktop. OAuth authorizations are visible under the Toolkit’s OAuth area and can be revoked there. For servers that use tokens, usernames, or other fields, follow that server’s configuration page instead.
- Connect your client. Open Clients, locate the AI application, and select Connect. Docker’s supported-client list can change, so a missing application should be treated as unsupported by the current Desktop release rather than forced through an unrelated connector.
- Verify both layers. Follow the client-specific verification instructions. For Claude, for example, you can inspect its MCP server list; in any client, send a prompt that invokes a tool from the server you added. A client connection alone proves Gateway connectivity, not that every selected server is configured correctly.
How the Docker MCP architecture works
MCP client
The client is the AI application that requests tools or resources. It does not need to know how each tool is packaged; it communicates with the Gateway using the connection method configured for that client.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
MCP server
A server exposes tools or resources. In the Toolkit Catalog, local servers run in Docker containers. Remote services run on the provider’s infrastructure and may require provider-specific authentication.
Profile
A profile is a named collection of configured servers. Selecting a profile determines which servers a Gateway-connected client can access, making separate profiles useful for isolating work projects, credentials, or experiments.
Gateway
The Gateway is the central proxy between the client and the selected servers. It routes each request to the appropriate server and starts a local server container when needed. The client therefore connects to one Gateway instead of maintaining a separate connection definition for every server.
Connect a client that Docker lists
The simplest route is the Clients > Connect button in Docker Desktop. After selecting a profile and connecting, restart or reload the client if its MCP list does not refresh automatically. Then test a specific tool, not merely the presence of a connection. If the tool reports missing credentials, return to the server’s configuration in the profile and complete its required fields.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Connect Claude Desktop or another named client from the CLI
The CLI reference provides a client command for supported applications:
docker mcp client connect <client> --profile <profile-id>
Use --global when you intentionally want to change system-wide client configuration instead of the current repository or project scope. Client names and available flags depend on the installed Docker Desktop release, so check the command’s help output if a name is rejected.
Use the CLI for repeatable setup
CLI setup is useful when you want a reproducible profile, a scripted workstation bootstrap, or a headless workflow. The documented command sequence is:
- Create a profile:
docker mcp profile create --name <profile-id> - Add a catalog server:
docker mcp profile server add <profile-id> --server catalog://<catalog-ref>/<server-id> - List the profile’s servers:
docker mcp profile server ls - Run the Gateway:
docker mcp gateway run --profile <profile-id>
Omit --profile from the Gateway command to use the default profile. Keep the profile identifier consistent with the one used by your client; otherwise the Gateway can start successfully while exposing the wrong server set.
Manual stdio configuration for an unlisted client
An unlisted MCP client can work if it can launch a local command over stdio. A generic JSON-based configuration commonly has this shape:
{
"mcpServers": {
"docker": {
"command": "docker",
"args": ["mcp", "gateway", "run", "--profile", "my-project"]
}
}
}
Replace my-project with your profile ID. The property names, file location, and whether the client expects an mcpServers object vary by application; use the client’s own configuration format. Claude Desktop, for example, uses its own mcpServers configuration shape. The important values are the docker executable and the argument sequence that starts the Gateway.
Rank #3
Choose local or remote catalog servers
| Characteristic | Local catalog server | Remote service |
|---|---|---|
| Where it runs | In a Docker container on your machine | On the provider’s infrastructure |
| Offline behavior | Docker says local servers work offline after they are downloaded | Requires the provider’s service and network access |
| Operations | Docker builds and signs the local catalog servers | Availability and implementation are controlled by the provider |
| Authentication | Depends on the server; may use tokens or OAuth | Often uses provider credentials or OAuth |
These are Toolkit-level distinctions, not a guarantee that every third-party service has identical behavior. Review the selected server’s configuration and permissions before adding it to a profile.
Authentication, permissions, and isolation
Configure only what a server needs
For an OAuth-capable server, add it first, open its configuration, choose OAuth, complete the browser authorization, and return to Docker Desktop. You can revoke an authorization from the OAuth section. Other servers may require a username, personal access token, API key, or a custom endpoint. For example, a Docker Hub MCP server documents username and personal access-token fields rather than assuming OAuth.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Understand the documented container controls
| Control | Documented Toolkit behavior | What you still need to review |
|---|---|---|
| CPU | 1 CPU limit for MCP tools | Whether a tool’s workload fits that limit |
| Memory | 2 GB limit for MCP tools | Large files, indexing jobs, and server-specific requirements |
| Host files | No host filesystem access by default | Any explicit mount you approve |
| Sensitive data | Requests to and from tools containing sensitive information, such as secrets, are blocked | Credentials, external service access, and the server’s own permissions |
These defaults reduce exposure but do not replace a permission review. An explicit mount, a powerful external token, or a remote provider can still grant consequential access.
Verify, update, and operate profiles safely
- Test a real tool: Ask the client to call one known tool and confirm the expected result.
- Inspect the active profile: If a tool is missing, check that it was added to the profile named in the client configuration.
- Separate credentials: Use different profiles for personal, work, and experimental services when access boundaries matter.
- Keep Desktop current: Beta UI labels and supported-client names can change; recheck the current command reference after an upgrade.
- Plan for startup cost: A local server may be started on demand by the Gateway, so the first call can take longer than later calls.
- Account for provider dependency: Remote servers depend on network connectivity and the provider’s service, even when the client and Gateway are local.
Common problems and fixes
Docker MCP Toolkit is missing from Settings
Confirm that Docker Desktop is on the release line that supports the documented Toolkit interface and that you are looking under Settings > Beta features. Restart Docker Desktop after updating or enabling the feature.
The client connects but no tools appear
Check the profile ID in the client configuration, list the profile’s servers, and confirm the server was added rather than merely viewed in the Catalog. Reload the client after changing its MCP configuration.
A server shows “Configuration Required”
Open that server from the profile and complete every required field. If the server uses OAuth, finish the browser flow and verify that the authorization appears in the OAuth area. If it asks for a token or username, do not substitute an OAuth flow.
The Gateway command exits immediately
Run the command directly in a terminal and verify that Docker Desktop is running, the profile exists, and the profile contains a valid server. Remove a manually added profile flag to test the default profile, or specify the intended profile explicitly.
A local server cannot reach a file
Host filesystem access is not provided by default. Review whether the server actually needs a mount and approve only the specific path required by the server’s configuration.
OAuth authorization is stale or belongs to the wrong account
Revoke the authorization in the Toolkit’s OAuth area, then repeat the server’s OAuth setup with the intended account. Check the active profile so the client is not using a similarly named server configured with different credentials.
An unlisted client rejects the JSON
The command may be correct while the schema is wrong for that application. Adapt the client’s required property names and configuration-file location, keeping the executable as docker and the arguments as mcp gateway run --profile <profile-id>.
Recommended Free Tools
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Or skip the browser setup
If your goal is simply to capture a webpage for an AI workflow, ScreenshotNeo provides a direct screenshot API and an MCP server for Claude, Cursor, and other MCP clients. One request returns PNG, JPEG, WebP, or PDF without you managing a browser container.
With the API, cookie and consent banners are accepted and removed before capture, along with more than 60 known consent platforms, newsletter popups, and chat widgets; each cleanup step can be disabled. Bot checks, CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.
cURL
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
Node.js
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
See the ScreenshotNeo API documentation for the full option set, including full-page lazy-image loading, CSS-selector element capture, device presets, dark mode, retina scale, PDFs, custom CSS and JavaScript, click actions, waits, request blocking, headers, cookies, geolocation, signed links, asynchronous jobs, bulk capture, caching, and usage reporting. Its MCP server exposes take_screenshot, get_page_info, and capture_pdf to AI agents.
Every plan includes all features: 1,000 screenshots per month are free with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
FAQ
Frequently Asked Questions
Can one AI client use different Docker MCP profiles?
Yes. Configure separate client entries or launch commands with different profile IDs, then verify which entry is active before invoking a tool.
Do remote catalog servers run inside my Docker Desktop installation?
No. Docker describes remote services as running on provider infrastructure; only local catalog servers are containerized on your machine.
Can I use the Toolkit without granting host-folder access?
Yes. Host filesystem access is off by default. A server only receives a mount when you explicitly select one, although it may still access external services through its configured credentials.
What should I check after upgrading Docker Desktop?
Reconfirm the beta feature is enabled, review the supported-client list, and run the Gateway and client-connect help commands because beta labels and flags can change.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

