---
sourceDocument: Brazil Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# Managing your AI Gateway

# Managing your AI Gateway {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Managing your AI Gateway

The AI Gateway in the MCP server record serves as a managed proxy between AI agents and external MCP servers.
It centralizes authentication, enforces policies, and provides observability for tool calls by routing AI agent connections through the gateway instead of direct access to MCP servers.
The AI Gateway tab in the MCP server record allows ServiceNow customers to review and manage connectivity endpoints, client integrations, tool configurations, and gateway policies.
Show full answer Show less  

## Key Features

* **Setup Sub-tab:** Displays MCP server connection endpoints and lists MCP clients registered to use the server through the AI Gateway. MCP clients represent AI agent hosts, developer tools, or integrated platforms consuming MCP server tools. Customers can add or edit MCP clients here.
* **Tools Sub-tab:** Lists tools exposed by the MCP server via the AI Gateway. Tools undergo a security scan based on the OWASP MCP Top 10 threat categories before activation. Scanning helps identify potential risks such as credential harvesting, excessive permissions, execution risks, exfiltration, and others. System properties control scanning activation and advanced analysis.
* **Policies Sub-tab:** Enables management of data governance policies at both the server and individual tool levels. Includes control over the Data sensitivity check, which inspects tool inputs and outputs to prevent sensitive data from passing between AI agents and the MCP server.

## Key Outcomes

* Centralized management of AI Gateway connections ensures secure and controlled access to MCP server tools.
* Comprehensive security scanning of MCP server tools reduces the risk of vulnerabilities and malicious behavior in AI interactions.
* Data sensitivity policies help enforce data governance by preventing sensitive information leakage during AI tool usage.
* ServiceNow customers can easily monitor and configure AI Gateway settings, client integrations, tool exposure, and policy enforcement from a single interface within the MCP server record.  
Manage your AI Gateway tab on the MCP server record.

The AI Gateway tab displays the configuration for exposing the MCP server to AI agents. Use the tab to review connectivity endpoints, manage MCP client integrations, configure available tools, and apply gateway policies to the
server.

## AI Gateway in MCP server record {#managing-your-ai-gateway__ai-gateway-mcp-server-record}

The AI Gateway acts as a managed proxy between AI agents and external MCP servers. When an AI agent needs to use tools from an MCP server, it connects through the AI Gateway rather than directly to the external server. This approach
centralizes authentication, helps enforce policies, and provides observability for tool calls.

The AI Gateway tab provides a complete view of how a specific MCP server is integrated with the AI Gateway. It is divided into three sub-tabs:
{#managing-your-ai-gateway__ai-gateway-mcp-server-record__entry__2}

| Sub-tab | Description |
|-|-|
| Setup | Displays the AI Gateway MCP server connection details and the MCP clients integrated with this server. This is the default sub-tab. |
| Tools | Lists the tools exposed by this MCP server through the AI Gateway and allows tool-level configuration. |
| Policies | Lists the gateway policies applied to this MCP server, such as rate limiting, access control, and usage policies. |
[ ]

## Setup {#managing-your-ai-gateway__setup}

The Setup sub-tab is the default view of the AI Gateway tab. It displays the endpoints that clients and agents use to connect to this MCP server through the AI Gateway. It also lists the MCP clients
registered to use this server.

**AI Gateway MCP server details panel**

The AI Gateway MCP server details panel displays the ServiceNow-generated endpoints that clients and agents use to connect to this MCP server
through the AI Gateway.

**MCP client integration panel**

The MCP client integration panel lists all MCP clients registered to use this MCP server through the AI Gateway. The count badge next to the panel heading
shows the total number of registered clients.

An MCP client is a consumer of the MCP server's tools --- typically an AI agent host application, a developer tool, or an integrated platform. MCP clients connect to the AI Gateway MCP
server URL to invoke tools.

To register a client, select Add client. After registration, clients can be edited on the Edit Client page.

## Tools {#managing-your-ai-gateway__tools}

The Tools sub-tab lists the tools exposed by the MCP server through the AI Gateway and allows tool-level configuration.

Before MCP server tools are activated, the system scans them to determine whether they pose a potential security threat. Threat categories are based on the OWASP MCP Top 10, the ten most critical MCP-related security vulnerabilities
as defined by OWASP. For more information, see [OWASP MCP Top 10](https://owasp.org/www-project-mcp-top-10/).

System properties control whether Now Assist Guardian tool scanning and more advanced scanning are enabled. For more information, see [System properties for AI Control Tower](https://www.servicenow.com/docs/JFyEETgY5vGZ0wf5IVVt3A "Several system properties that affect core AI Control Tower are available.").
{#managing-your-ai-gateway__tools__entry__2}

| Threat category | Description |
|-|-|
| credential_harvesting | Potential collection or exposure of sensitive credentials. |
| excessive_permissions | Optional parameters potentially granting dangerous capabilities beyond their stated purpose. |
| execution | Potential shell commands, code evaluation, or subprocess spawning. |
| exfiltration | Potential unauthorized data export to external destinations. |
| hidden_instructions | Potentially concealed directives using steganography or authority-framing manipulation. |
| name_description_mismatch | Tool name potentially implies a different function than the description or schema reveals. |
| network | Potential unauthorized network access (SSRF, DNS rebinding, or arbitrary URLs). |
| none | No potential threats detected. |
| obfuscation | Encoded content (base64, hex, URL-encoded) potentially concealing true behavior. |
| prompt_injection_payload | Potential direct prompt injection. For example, a phrase such as "ignore all previous instructions". |
| tool_poisoning | Description contains instructions that could potentially manipulate agent behavior. |
| write | Potential unauthorized file system modifications. |
[ ]

Scan status indicates the current state of the MCP tool scan. Possible values are:

* Completed
* Failed
* Pending
* Timeout
{#managing-your-ai-gateway__ul_mfn_wbl_njc}

## Policies {#managing-your-ai-gateway__policies}

The Policies sub-tab lists the data governance policies applied to the server. From the Policies sub-tab, you can manage policy enforcement at the server level and the individual tool level.

**Data sensitivity check**

The Data sensitivity check area controls whether the AI Gateway inspects tool inputs and outputs for sensitive data. When enabled, this setting prevents sensitive data from passing between AI agents and the MCP server.

**Policy status table**

The policy card displays the current server-level state of the Data sensitivity check policy and provides a control to change it.
{#managing-your-ai-gateway__policies__entry__2}

| Policy status | Description |
|-|-|
| Activated | The Data sensitivity check is enabled at the server level. The Deactivate button is available. Enforcement still depends on individual tool-level Policy status settings. |
| Deactivated | The Data sensitivity check is disabled at the server level. No sensitive data inspection occurs for any tool on this server, regardless of tool-level Policy status. Select Activate to turn it on. |
[ ]


