Docker MCP Gateway has no universal TCP port. The docker mcp gateway run command uses stdio by default, so it listens to its launching client instead of opening a network socket. Port 8811 is used in Docker’s official agentic-AI Compose example, where the gateway runs over SSE at http://mcp-gateway:8811/sse. Your actual port is whatever you set with --port when selecting the sse or streaming transport.
The direct answer
There are three cases to distinguish:
| Setup | Transport | Does it use a TCP port? | Client connection |
|---|---|---|---|
docker mcp gateway run --profile <profile-id> with default options |
stdio |
No | The client launches the Docker command directly. |
Gateway started with a network transport and --port N |
sse or streaming |
Yes, port N |
Use the endpoint and route configured for that deployment. |
| Docker’s agentic-AI Compose example | sse |
8811 |
http://mcp-gateway:8811/sse |
The official command reference describes --port as the “TCP port to listen on” and says the default is listening on stdio. It does not assign a numeric default port.
Why a normal CLI run has no port
stdio means standard input and standard output. A client starts the gateway process and exchanges messages through that process’s input and output streams. Since communication is local to the process relationship, there is no TCP listener to discover, publish, or add to a firewall rule.
This is why a command such as the following can work without a port number:
#1 Best Overall
docker mcp gateway run --profile <profile-id>
The profile selects the gateway configuration; the default transport remains stdio. A manually configured MCP client must therefore be set up to launch this command rather than to connect to localhost or another host and port.
When Docker MCP Gateway does use a port
Select a network transport
The command reference lists stdio, sse, and streaming as supported transport values. A TCP listener is relevant when you select sse or streaming. Set the listener explicitly with --port:
docker mcp gateway run
--profile <profile-id>
--transport=sse
--port=8811
The number in this example is a choice, not a built-in default. Replace it with the port that your host, container, orchestrator, and client configuration agree to use.
Use the complete endpoint, not only the number
A network client needs a scheme, host, port, and route. The port alone is insufficient. In the Compose example, the endpoint is:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →http://mcp-gateway:8811/sse
Here, mcp-gateway is the Compose service name, 8811 is the configured TCP port, and /sse is the SSE route. Other deployments may use a different host, port, or route; read those values from the actual command and Compose configuration.
What port 8811 means in the Compose example
Docker’s official “Build and run agentic AI applications with Docker” Compose example sets the application environment variable to:
MCPGATEWAY_ENDPOINT=http://mcp-gateway:8811/sse
The same gateway service starts with --transport=sse. Those two settings make 8811 the port for that particular deployment. It is not a universal Docker MCP Gateway port and should not be assumed for an unrelated installation.
If you edit the Compose command to use another value, change the client endpoint to match. If the gateway is exposed outside the container network, the host-side published port must also correspond to the endpoint your client can reach; an internal container port and an external published port are deployment details, not fixed gateway defaults.
Rank #3
How to identify the correct port in an existing deployment
- Inspect the gateway command. Look for
--transportand--port. If--transportis absent, treat it asstdiounless your wrapper supplies another value. - Check the service environment. Find variables such as
MCPGATEWAY_ENDPOINTin the application or agent service. Copy the host, port, and path exactly. - Compare both sides of a Compose setup. The gateway’s
--portvalue and the client endpoint’s port must refer to the same reachable socket for that network. - Confirm the route. For the documented SSE example the route is
/sse. A correct port with an incorrect path can still produce a 404 or an immediate disconnect. - Determine whether the client expects stdio or a network transport. A stdio client should launch the Docker command; an SSE or streaming client should use the configured URL.
Choosing stdio, SSE, or streaming
stdio
- No TCP port is required.
- The MCP client and gateway are connected through the launched process.
- Use the direct
docker mcp gateway run --profile <profile-id>form when your client supports launching commands.
SSE
- Requires a TCP port selected with
--port. - Clients connect to an HTTP endpoint whose route must be configured correctly; Docker’s Compose example uses
/sse. - Use the exact host name that is reachable from the client. A Compose service name normally works only for services sharing the relevant Compose network.
Streaming
- Also requires a configured TCP port.
- The endpoint path and client settings depend on your deployment; do not copy the SSE
/sseroute unless your streaming configuration defines it.
Troubleshooting port and endpoint errors
“Connection refused”
The gateway may not be running, may still be using stdio, or may be listening on a different port than the client is calling. Check the active --transport and --port values, then make the endpoint match.
“Address already in use” when starting the gateway
Another process is already bound to the selected TCP port. Choose an available number with --port and update every client endpoint that points to the old value. There is no automatic universal replacement port to rely on.
HTTP 404 or an SSE client that disconnects immediately
The host and port can be correct while the route is wrong. Verify the complete path. The documented Compose endpoint ends in /sse; a client pointed at the server root is not equivalent.
The CLI client works, but a URL-based client cannot connect
This usually indicates a transport mismatch. A successful stdio launch proves only that the local process connection works. Start the gateway with --transport=sse or --transport=streaming, assign --port, and configure the URL-based client for that transport.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #4
The container can resolve neither the host nor the port
Check that the client and gateway are attached to the expected container network and that the endpoint uses the gateway’s reachable service name. The Compose example uses mcp-gateway as an internal host; that name is not automatically a public DNS name.
The endpoint works inside Compose but not from a host machine
Compare the internal container port with the host-published port in your deployment. A client outside the Compose network may need the host address and published port rather than the internal service name and container port.
Operational notes before exposing a TCP listener
- Keep configuration authoritative. Treat the gateway command and the client endpoint as one unit. Changing
--portwithout changing the endpoint creates a predictable connection failure. - Prefer stdio when a local client can launch the command. It avoids choosing and publishing a network port altogether.
- Use a network transport when process boundaries require it. SSE and streaming make the gateway reachable through a configured socket, but they introduce host, route, and network-visibility settings that must agree.
- Limit exposure deliberately. A TCP listener should be reachable only from the clients and networks that need it. Apply your normal container-network and firewall controls rather than assuming that port 8811 is private or public.
- Do not infer capacity or performance from the port number. The number identifies a listener; it says nothing about throughput, latency, or reliability.
Or skip the browser setup
If you need a clean screenshot of gateway documentation, an internal status page, or another web page while preparing an MCP integration guide, ScreenshotNeo provides a single HTTP call instead of a browser-automation setup. It accepts consent banners as a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and the response identifies the page and billing result with X-Page-Verdict and X-Billed headers. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for Claude, Cursor, and other MCP clients.
See the ScreenshotNeo API documentation for request options. A cURL request is:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
The same request in Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
And in Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Replace the example URL with the page you are allowed to capture. ScreenshotNeo includes full-page and lazy-image loading, CSS-selector element capture, device and viewport controls, custom CSS and JavaScript, waits, request blocking, cookies and headers, PDFs, caching, signed links, asynchronous jobs, webhooks, bulk capture, and a usage API. Every feature is available on every plan. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 screenshots.
Best Value
Create a free ScreenshotNeo account to use the 1,000 monthly screenshots without adding a card.
FAQ
Can I connect to the gateway without knowing any port?
Yes. Configure an MCP client to launch the gateway command over stdio. A port becomes necessary only when your chosen transport communicates over the network.
Is 8811 reserved by Docker?
No. It is simply the value selected in Docker’s documented SSE Compose example. Another deployment can choose a different port with --port.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhy does an endpoint include both a port and a path?
The port identifies the TCP listener, while the path selects the gateway route handled by that listener. Both parts must match the transport configuration.
Frequently Asked Questions
Can I connect to the gateway without knowing any port?
Yes. Configure an MCP client to launch the gateway command over stdio. A port becomes necessary only when your chosen transport communicates over the network.
Is 8811 reserved by Docker?
No. It is simply the value selected in Docker’s documented SSE Compose example. Another deployment can choose a different port with –port.
Why does an endpoint include both a port and a path?
The port identifies the TCP listener, while the path selects the gateway route handled by that listener. Both parts must match the transport configuration.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

