Every server you build in GetMCP has its own URL, and until now every one of them had to be added to every AI client separately. Ten servers, ten connector entries — in Claude, in Cursor, in ChatGPT. 1.6.0 gives your whole install one address. It also connects the system most of your data actually lives in: a database. And it makes the first connection a single click.
The MCP Gateway: one endpoint for every server
Turn on the gateway and your install answers at https://your-site.com/mcp. Connect a client there once and it sees the tools of every server behind it. Build a new server next month and it appears in that client on its next refresh — nothing to reconfigure. Your individual server endpoints keep working exactly as before; the gateway is an addition, not a migration.
Tools arrive prefixed with the server that owns them — orders__search_orders, crm__search_contacts — which is what lets two servers both have a search tool. A call is handed to the server that owns it and runs exactly as it would through that server’s own URL: same credentials, same rate limits, same logs. Nothing is duplicated and nothing is proxied through a second hop.
The gateway has its own front door. Pick how clients authenticate to it — OAuth (the client registers itself and opens a browser sign-in, nothing to copy), an API key, a bearer token, or open for local testing — separately from how each server authenticates. And choose what it publishes: every server, or only the servers you choose. That second mode matters more than it sounds. Every tool behind the gateway is sent to the model on each request, and models get less accurate as the list grows, so the Gateway screen tells you the exact tool names a client will see and warns you when the list is long enough to hurt.
One rule we were careful about: an open gateway carries only servers that were already open. A server that requires its own credential is held back and listed as withheld, never quietly turned into a public one. If you want it behind an open gateway, you name it explicitly. The built-in GetMCP server — the one that manages your install — is never published through the gateway at all.
Your database, as MCP tools
Install Database (MySQL / PostgreSQL) from Templates, enter the host, database, username and password under Settings → Database, click Test connection, and your AI client can explore and query it. It works with a database on your own server, a managed one from your host, and the cloud services people actually use — Supabase, PlanetScale, Neon, Amazon RDS, DigitalOcean. The password is encrypted with your installation’s own key and stored in your own database; query results move directly between your server and the database and never pass through getmcp.com.
Nine tools come with it. Five only read, and they are on from the start:
list_tables— the tables and views, with an estimated row count and any commentdescribe_table— one table’s columns, primary key, indexes and foreign keysrun_query— aSELECT(orWITH,SHOW,EXPLAIN) with bound parametersget_rows— rows from one table by simple filters, sorted and paged, with no SQL at allcount_rows— how many rows match a filter, exactly
The four that change data — insert_row, update_rows, delete_rows and execute_sql — install switched off. And turning one on is only the first of two locks. The connection itself starts read-only, and that is enforced by the database engine on the session, not by pattern-matching your SQL, so an unusual statement cannot slip past it. To let an AI change data you enable the tool and untick Read-only connection. update_rows and delete_rows also refuse to run without a filter, so “update every row” cannot happen by accident.
Databases are big, and the tools admit it. Every connection has a row cap (200 by default, up to 1,000) and a statement timeout; long text is trimmed and binary columns are summarised, so one wide table cannot flood a conversation. A good AI client calls list_tables and describe_table first and then writes queries against the real column names — ask it “how many orders were placed last month, and what was the total?” and watch it do exactly that.
Using Supabase? It is a PostgreSQL database with one detail that matters — which of its three connection strings you use — and we wrote it up: Creating a Supabase database MCP server without coding. The general guide is Connect a database.
Quick Connect: one click to Claude or Cursor
At the top of every server there are now two buttons. Connect to Claude opens claude.ai on the Connectors screen with the custom connector’s name and URL already filled in — you check the URL, click Add, and the connector runs on the Claude plan you already have. Connect to Cursor installs the server straight into Cursor’s MCP settings through a deep link. They replace the old “Use in Claude” button.
Before handing the server over, GetMCP runs the checks that would otherwise fail silently on the other side: is the site reachable from the internet, is it served over HTTPS, does the server have authentication the client can complete, does it have active tools, is it active. If something would stop the connection, the button opens a panel that names it and says what to change — a .local address, for instance, works for Cursor on your machine but not for Claude, which connects from Anthropic’s servers.
The WordPress template covers a site properly
The WordPress template used to be a handful of read tools. It is now 17 tools across posts, pages, custom fields, categories, tags, media and users — and the one people asked for most, update_post, so an AI can revise an existing draft instead of creating a new one. get_post can return the raw, unrendered source of a post, so what the AI edits is what is actually there.
Two things are deliberate. delete_post and create_user install switched off. And if you want publishing to stay in your own hands, delete the status parameter from create_post and update_post — an argument a tool does not declare never reaches WordPress, and WordPress defaults to draft. The AI can write and revise all it likes; only you press publish.
Templates that point at a site of yours now ask for the address once. Install the WordPress or WooCommerce template, type your domain, and every tool in it is built from that value — no more editing the same placeholder into seventeen URLs by hand. The address lives under the server’s Connection Variables, which only you can change, so no AI client can redirect the tools somewhere else.
Plays well with other MCP plugins
If you run another MCP plugin on the same WordPress site — Novamira, FlowMattic’s MCP server, or anything else that signs clients in through OAuth — GetMCP now stays off the site-root discovery paths those plugins depend on. GetMCP never needed them: its own discovery lives under each server’s URL. System Status shows which plugin answers the site root, and a filter lets you switch GetMCP’s fallback off entirely. On a site running both, each plugin’s clients sign in to the right place.
Also in 1.6.0
- ChatGPT connects through OAuth again. The consent redirect now carries the
issparameter ChatGPT validates, and the gateway’s discovery answers at the exact URL its challenge names. If ChatGPT ever told you “there was a problem connecting” right after you approved, this was it. - A broken JMESPath selector fails loudly. A tool whose selector cannot be applied now says so instead of quietly returning the entire unfiltered response — which cost tokens on every call and handed the AI exactly the fields the selector existed to remove. System Status also reports whether the filtering engine is present.
- Existing servers pick up new connector tools in place, for the database connector exactly as for the mailbox: a notice under Settings offers to add what is missing, leaving your connection and the tools you had enabled untouched.
- The Tool Editor’s Test panel runs connector tools — mailbox and database — instead of trying to resolve an endpoint they do not have.
- The OAuth consent screen shows the connecting client’s mark clearly in dark mode, and Gateway has its own entry in the WordPress admin menu.
- Standalone app: System Status describes the scheduler and the storage directories it actually checks, instead of WP-Cron wording on an install that has no WordPress.
Getting 1.6.0
If you’re on the WordPress plugin, the update is waiting in your dashboard. On the standalone app, System Status will offer it, or update from the command line:
curl -fsSL https://get.getmcp.com | bash -s -- --update --dir=/path/to/getmcp
Both builds are the same codebase, so the gateway, the database connector and Quick Connect behave identically on either. The gateway is off until you turn it on under GetMCP → Gateway; What is the MCP Gateway? and Enable the MCP Gateway walk through it. The full list of changes is on the changelog, and if you hit anything odd, support is the fastest way to reach us.
Related posts
Start Here: Understanding MCP
New to the Model Context Protocol? These are the pieces worth reading, in the order that makes sense…
MCP vs an API: What Actually Changes
If you already have a REST API, why would you add an MCP server? Because an API is…
What Can You Actually Do with an MCP Server?
"MCP lets AI use your tools" is true and tells you nothing. Here are the six things people…
[…] in Connect a database. And if the database is one of several things you want your AI to reach, the MCP Gateway publishes this server alongside every other one at a single […]
[…] its own application password — and if you want them all in your AI at one address, turn on the MCP Gateway: the tools arrive as blog__update_post, docs-site__update_post and so on, so the AI always knows […]