Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Docker MCP is Docker’s set of tools for finding, configuring, isolating, and connecting Model Context Protocol (MCP) servers to AI applications. It is not one standalone server. The ecosystem combines a curated Catalog, the Docker Desktop MCP Toolkit, project-oriented profiles, and the MCP Gateway that routes requests between an MCP client and servers.

MCP itself is an open standard: an AI application acts as a client, while an MCP server exposes tools or data. Docker packages the operational pieces so you can select servers, supply credentials, run them in containers, and make them available to compatible clients.

Docker MCP at a glance

Component What it does Where it fits
MCP Standard protocol for connecting AI applications to external tools and data. The communication model used by clients and servers.
Docker MCP Catalog Curated library of server definitions and container images. Discovery: what servers are available.
MCP Toolkit Docker Desktop interface for adding, configuring, grouping, and connecting servers. Management: how you set up a workflow.
Profiles Named collections of selected servers. Organization: which tools belong to a project or environment.
MCP Gateway Open-source proxy and orchestrator that routes requests, manages configuration and credentials, starts and stops servers, and applies access controls. Runtime: how an AI client reaches the selected servers.

Docker’s current overview reports 300+ verified servers in the Catalog (documentation accessed September 29, 2026). “Verified” refers to Docker’s catalog process, not a guarantee that a server or its output is safe.

How a Docker MCP request works

  1. You choose a server from the Catalog, such as a service integration or database tool.
  2. You add it to a profile in the Toolkit and provide its configuration or authorization.
  3. Your MCP-compatible AI application connects to that profile through the Gateway.
  4. The client requests a tool. The Gateway identifies the responsible server, starts or reuses its container, forwards the request, and returns the response.

Gateway-managed servers run in containers with restrictions on privileges, network access, and resource usage. With the Toolkit enabled in Docker Desktop, the Gateway runs in the background. If you use Docker Engine without Docker Desktop, Docker documents a separately installed Gateway option.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Catalog, profiles, Toolkit, and Gateway: the distinctions that matter

Catalog versus profile

The Catalog is the library; a profile is your selection. A Catalog entry can be available to many projects, while a profile limits the servers exposed to one workflow. Separate profiles reduce accidental access—for example, keep production database tools out of a writing assistant’s profile.

Toolkit versus Gateway

The Toolkit is the Docker Desktop management interface. It helps you discover entries, configure authentication, create profiles, and connect clients. The Gateway is the service doing the runtime work: routing calls, managing server lifecycle, and enforcing its boundaries. You can use the Gateway independently of the Desktop interface when running Docker Engine.

Docker Desktop versus Docker Engine

Desktop provides the integrated Toolkit and a background Gateway. Engine users without Desktop install and operate the Gateway separately, so setup, upgrades, and client configuration are more explicit. Docker’s documented Toolkit interface applies to Docker Desktop 4.62 and later; older releases may show different labels or flows.

Setting up Docker MCP in Docker Desktop

The exact labels can change because the Toolkit is currently marked Beta. On a current Desktop release, the practical sequence is:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Open Docker Desktop and select the MCP Toolkit area.
  2. Browse the Catalog and choose a server. Read the server’s required environment variables, scopes, and network needs before adding it.
  3. Add the server to a new or existing profile.
  4. Configure credentials. For services supporting OAuth, the Toolkit can open browser authorization and retain the resulting credentials for the integration.
  5. Enable the profile and connect your MCP client using the Gateway connection details shown by Desktop.
  6. In the AI application, confirm that the expected tools are listed, then test with a low-risk request before granting write access or production credentials.

Removing a server does not automatically delete credentials stored in the Docker Desktop VM (the FAQ documents this behavior starting with Desktop 4.43.0). Remove or revoke those credentials separately when decommissioning an integration.

Security model: useful controls, not a safety guarantee

Build and provenance controls

For Docker-built catalog images, Docker documents digital signatures, attestations, and software bills of materials. Most catalog servers are built by Docker; selected third-party servers are built in ephemeral environments and checked for initialization, basic functionality, and whether their tools can be listed.

Runtime boundaries

  • A documented one-CPU limit and two-gigabyte memory limit apply to Toolkit-managed servers.
  • Host-filesystem access is denied by default.
  • Requests containing sensitive information can be intercepted.
  • When signature verification is enabled for images in Docker Hub’s mcp/ namespace, images must be referenced by digest.

What these controls do not cover

Docker explicitly describes its security measures as best effort, not exhaustive: “Docker’s security measures currently represent a best-effort approach. While Docker implements automated testing, scanning, and metadata extraction for each server in the catalog, these security measures are not yet exhaustive.” Isolation and provenance can limit some failures, but they do not make every server trustworthy.

The Gateway security model also does not claim to stop prompt injection or malicious content returned by a tool, README, remote service, or upstream API unless that content crosses a documented Gateway boundary. Treat tool output as untrusted input, review requested permissions, use least-privilege tokens, and avoid placing secrets in prompts or unrestricted environment variables.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choosing a safe operating pattern

For experimentation

  • Use a profile containing only the server you are evaluating.
  • Use test accounts and read-only scopes.
  • Keep filesystem access disabled unless the workflow genuinely needs it.
  • Inspect the tools exposed by the server before allowing an agent to call them.

For team projects

  • Create one profile per project or environment rather than one universal profile.
  • Document who owns each credential and how it is revoked.
  • Pin images by digest where signature verification is required.
  • Separate development and production clients and credentials.

For production automation

Define explicit approval boundaries for writes, rotate credentials, monitor Gateway and server logs, and test failure behavior. Container isolation reduces blast radius; it does not replace application-level authorization or review.

Common problems and fixes

The client cannot see any tools

Confirm that the profile is enabled, the client is connected to the Gateway rather than directly to a stopped server, and the server finished initialization. Reconnect the client after changing a profile.

OAuth authorization keeps returning to the login page

Check that the browser completed consent, the redirect was allowed, and the service account has the required scopes. Remove stale credentials from Desktop’s stored credential area and authorize again.

A server starts and then exits

Inspect its required environment variables, image architecture, and initialization logs. Resource limits are intentional; a server that exceeds the documented one-CPU or two-gigabyte boundary may fail until its workload or configuration is reduced.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Signature verification rejects an image

Use an image from the expected mcp/ namespace and reference the digest when verification is enabled. Do not disable verification merely to make an untrusted image run.

The agent receives suspicious instructions in tool output

Stop the operation, treat the content as prompt injection, and review the server and upstream response. Gateway routing and container boundaries do not automatically neutralize malicious text returned by a tool.

Docker MCP’s current status

The Toolkit is Beta, so UI details and supported integrations can change. Docker’s launch announcement on May 5, 2025 described a Catalog with 100+ servers; current documentation reports 300+. Those figures describe different dates, not a like-for-like independent measurement. The open-source Gateway and the Gateway feature in Docker AI Governance are also different offerings; the latter is documented as invite-only.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Or skip the browser setup

If your immediate goal is generating clean website screenshots for an AI workflow, ScreenshotNeo provides a website screenshot API and MCP server. Its one-call API accepts a URL and returns PNG, JPEG, WebP, or PDF. Before capture it can accept consent banners and remove more than 60 known consent platforms, newsletter popups, and chat widgets; each step can be disabled. Bot checks, blank pages, timeouts, failed loads, and cache hits are not billed, and response headers identify the page verdict and billing result.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

cURL:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Python:

import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);

See the ScreenshotNeo documentation for the full options, including full-page and element capture, device presets, custom CSS and JavaScript, waits, blocking rules, cookies and headers, PDFs, caching, bulk jobs, signed links, webhooks, and its MCP tools for AI clients. It includes 1,000 screenshots per month free with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.

Frequently Asked Questions

Is Docker MCP itself an MCP server?

No. Docker MCP is an ecosystem for discovering, configuring, running, and connecting MCP servers. Individual Catalog entries are the servers.

Do I need Docker Desktop to use the Gateway?

No. Desktop integrates the Toolkit and runs the Gateway in the background, while Docker Engine users can install the Gateway separately.

Does Catalog verification guarantee a server is safe?

No. Docker calls its controls best effort and not exhaustive. Review permissions, credentials, source, and tool behavior yourself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why are profiles useful?

They expose a deliberate set of servers for a project or environment, avoiding one broad collection of tools and credentials for every AI client.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.