Skip to content

docs(aigw): remove content that isn't true for Prisma AIRS, plus MCP OAuth 2.22.0 and Error Code 03 fixes - #1094

Merged
vrv-panw merged 13 commits into
mainfrom
docs/prisma-airs-updates
Oct 1, 2026
Merged

vrv-panw merged 13 commits into
mainfrom
docs/prisma-airs-updates

Conversation

@vrv-panw

@vrv-panw vrv-panw commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

A self-hosted SCM POC (AKS, CIE with Entra ID, gateway 2.21.0) couldn't get MCP OAuth 2.1 working: API-key access worked, and OAuth failed before any login page opened. Two things in the docs would have let them fix it themselves.

Changes

aigw/product/mcp-gateway/authentication/cas.mdx

  • New prerequisite 1: gateway 2.22.0 or later. On 2.21.0, GET /oauth/<slug>/authorize returns 500 {"status":"failure","message":"immutable"}, so the flow stops between client registration and the CAS login page. 2.22.0 fixed it (see the 2026-09-11 changelog entry).
  • Two troubleshooting rows: the 2.21.0 500, and the Error Code: 03 registration failure below.

aigw/help-center/mcp-gateway-troubleshooting.mdx

  • New section, Client registration fails with "Invalid API Key. Error Code: 03". That body comes from the AI Gateway: the MCP Gateway's /.well-known/*, /oauth/register and OPTIONS need no API key, and its own rejection is {"error":"unauthorized"} with WWW-Authenticate. The section gives three checks (discovery URLs, a test registration, the same request from inside the pod) and the fixes: MCP_GATEWAY_BASE_URL, routing every path on the MCP host to 8788 under SERVER_MODE=all, or SERVER_MODE=unified.
  • One paragraph on the unified-mode URL layout: servers under /m, discovery and OAuth at the root. Only the changelog mentioned this before, and it reads as if everything moves under /m.

How this was verified

Against a live self-hosted gateway (gateway_enterprise, unified mode), with no API key on any request:

Request 2.21.0 2.22.0
GET /.well-known/oauth-authorization-server 200 200
OPTIONS /oauth/register 204 + CORS —
POST /oauth/register 201 (also 201 with a bogus Authorization or x-portkey-api-key) 201
GET /oauth/<slug>/authorize 500 immutable 200, redirect to cloud-auth.us.apps.paloaltonetworks.com
POST to a non-MCP path 401 Invalid API Key. Error Code: 03 —

Not verified: SERVER_MODE=mcp / all on 8788. The in-pod check in the new section is there to tell a routing fault from a mode-specific one.

Checks

mint validate passes. mint broken-links --check-anchors flags nothing new; the three anchors it reports on the troubleshooting page are pre-existing and also appear on the non-aigw copy.

Also in this PR: removing claims that aren't true for Prisma AIRS

Six commits, all confined to aigw/ and snippets/aigw/:

  • ec431c9d AWS and Azure Marketplace. Retires self-hosting/hybrid-deployments/aws/marketplace (removed from nav, recorded in the retirement ledger). Drops the Azure Marketplace note from AKS, the marketplace cards from the Integrations overview, and the marketplace, strategy-call and demo CTAs from the Azure cloud page. Repoints private-cloud links that sent readers to the Latest version.
  • 08c782d0 Claims earlier sweeps missed: SOC 2 / ISO / GDPR / HIPAA and 99.995% uptime, "hosted on edge workers", the open-source npx @portkey-ai/gateway setup on Ollama, and the JWT "contact sales" upsell.
  • 1dad2cdb Prompt Studio text: 41 files. The prompts.* API key scopes, prompt_id and the cache-internals rows stay, because they are identifiers.
  • 0046b388 Plan tiers, generic enterprise copy, air-gapped and Portkey support: 143 files, air-gapped changelog items included. Vendors' own tiers, functional identifiers and the "Enterprise Gateway" component name stay. This also fixes 23 #3-enterprise-governance links on 14 library pages that were already broken.
  • 03f84fc4 Prompt permissions, Log Replay and remaining Portkey links: retires configure-prompt-access-permissions, removes the Log Replay section and budget-policies Use Case 9 (the rest are renumbered), and removes the community.portkey.ai card. The app.portkey.ai links in the governance snippet now point at Strata Cloud Manager.
  • eb331f3f Registry API host: the endpoint moves from aigw.portkey.ai/m/v0.1/servers to the MCP Gateway host, mcp-aigw.portkey.ai/v0.1/servers. The examples go back to the x-portkey-api-key header, which matches the page's note that Bearer isn't accepted.

mint validate, check_nav_page_parity.py and check_anchors.py pass.

🤖 Generated with Claude Code

…during registration means

Two gaps a self-hosted SCM POC hit in the field:

- cas.mdx listed no minimum gateway version. On 2.21.0 GET /oauth/<slug>/authorize
  returns 500 {"message":"immutable"}, so the flow dies between client registration
  and the CAS login page. Added as prerequisite 1 and a troubleshooting row.
- A client reporting "Dynamic Client Registration rejected (HTTP 401)" with
  "Invalid API Key. Error Code: 03" is talking to the AI Gateway, not the MCP
  Gateway, whose /oauth/register takes no API key. The troubleshooting page now
  says how to tell the two apart, how to confirm from inside the pod, and the
  base-URL / routing / unified-mode fixes. It also notes that unified mode keeps
  /.well-known and /oauth at the root while servers move under /m.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@mintlify

mintlify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
portkey-docs 🟢 Ready View Preview Oct 1, 2026, 10:44 AM

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Clarify unified-mode /m URLs and the gateway 2.22.0+ requirement.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Low severity

Open (1)
What changed in this PR

Documents MCP OAuth prerequisites and troubleshooting for self-hosted gateways.

Changes:

  • Requires gateway 2.22.0+ for SCM CAS OAuth.
  • Adds Error Code 03 registration diagnostics and routing checks.
  • Clarifies unified-mode URL behavior.
File Summary
aigw/​product/​mcp-gateway/​authentication/​cas.mdx Adds version requirements and OAuth troubleshooting entries.
aigw/​help-center/​mcp-gateway-troubleshooting.mdx Adds registration diagnostics and deployment guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread aigw/help-center/mcp-gateway-troubleshooting.mdx Outdated
roh26it and others added 2 commits September 27, 2026 17:23
The misrouted-OAuth failure and the unified-mode URL layout apply to any
self-hosted gateway, not only Prisma AIRS. The CAS prerequisite stays
aigw-only because CAS is a Palo Alto Networks service.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Correct the troubleshooting commands and scope the routing and version guidance.

Review effort: Lite
Findings: 3 Low severity

Open (3)

Comment thread aigw/help-center/mcp-gateway-troubleshooting.mdx Outdated
Comment thread help-center/mcp-gateway-troubleshooting.mdx Outdated
Addresses the Copilot review comment: step 1 gives /{slug}/mcp, but
unified mode serves MCP under /m. The Confirm steps probe port 8788,
which exists only with SERVER_MODE=all or mcp; start-server.ts routes
/.well-known and /oauth to the MCP app in unified mode.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses the Copilot review comment: step 3 said "repeat it" but ran a
GET for discovery metadata, which can succeed while /oauth/register is
misrouted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The registration diagnostic is incomplete and version guidance needs correction.

Review effort: Lite
Findings: None

Resolved since last review (3)
Previously missed (1)

In code that hasn't changed since last review

Low severity Health endpoint cannot verify deployed version

aigw/​product/​mcp-gateway/​authentication/​cas.mdx:49

GET /v1/health is documented elsewhere in this repository as returning only Server is healthy, so it is a liveness check rather than a way to identify whether the running deployment is 2.21.0 or 2.22.0. Point readers to the deployed image/release tag (or a version-bearing endpoint) instead; otherwise they cannot verify this prerequisite as instructed.

Copilot AI review requested due to automatic review settings September 27, 2026 12:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Moderate issues remain in routing scope and authorization-server metadata guidance.

Review effort: Lite
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Medium severity Apply the routing correction to standalone MCP deployments

aigw/​help-center/​mcp-gateway-troubleshooting.mdx:256

The preceding confirmation steps explicitly apply to both SERVER_MODE=all and SERVER_MODE=mcp, but this fix only tells all deployments to route every path. A standalone mcp deployment can have the same host/ingress misroute and needs the same correction; include mcp here or explain its distinct routing requirement.

vrv-panw and others added 4 commits September 28, 2026 14:53
Prisma AIRS AI Gateway is not sold through either marketplace; every
mention pointed at Portkey's own listings.

- Retire self-hosting/hybrid-deployments/aws/marketplace (nav entry
  removed, recorded in the retirement ledger)
- Drop the Azure Marketplace note from the AKS guide and both
  marketplace cards from the Integrations overview
- Azure cloud page: replace the 1-click Marketplace card and step with
  the AKS / ACA hybrid guides, and remove the strategy-call CTA,
  Book-a-Demo iframe and unsourced "75% faster" stats
- Repoint private-cloud-deployments links that escaped to the Latest
  version (mongodb, prometheus-metrics, azure) at the aigw hybrid guides

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Residue from Phases 3 and 5, which removed these claims elsewhere:

- SOC 2 / ISO 27001 / GDPR / HIPAA claims on security, audit-logs and
  the Arize page, and the 99.995% uptime line
- "Hosted on edge workers" in the Welcome FAQ
- The open-source `npx @Portkey-AI/gateway` local setup on Ollama
- JWT "contact sales / add-on to your plan" upsell
- "Enterprise customers and select Pro users" and "Enterprise users"
  tier gates on workspace budgets and MongoDB

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Prompt Studio and the prompt endpoints are not part of Prisma AIRS AI
Gateway (dropped in Phase 1 and upstream in the spec). Phase 1 stripped
the links; this removes the prose that still told readers to use them.

- Agent pages (7): the "Prompting in <framework>" section with its
  Playground / Templates / Versioning tabs, the "Version-controlled
  prompts" intro bullet, and later numbered headings renumbered
- LLM pages (12): "Managing <Provider> Prompts" sections; the
  "prompt management" item dropped from 19 provider intros
- Libraries: empty Prompt Management / Prompt Templates stubs
  (langchain, llama-index, vercel, openai-agent-builder x2)
- Product: prompt sections in function-calling and vision, prompt IDs
  and the prompt-template Replay caveat in logs, prompt endpoints in
  the guardrails capabilities tables, Prompt Playground in fine-tuning
- Prompt caching (Anthropic, Bedrock): prompt-template mentions
- Help Center: Prompt Studio and the prompt completions endpoint row

Left alone as functional identifiers or gateway internals: permission
scopes (`prompts.*`), config `prompt_id`, the budget-policy `prompt`
key, cache object types, sync payload types, KMS object list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y support

Prisma AIRS AI Gateway has no plans or tiers, is offered as managed and
hybrid only, and is not supported through Portkey's support desk.

- Plan tiers: drop the "available on all plans" callouts (19 pages), the
  guardrails tier table and "select Enterprise customers only"; reword
  "self-hosted Enterprise" / "Hybrid enterprise customers" to hybrid
- Generic enterprise copy: "Enterprise Features Now Available",
  "Enterprise Governance", "for enterprise customers", "enterprise-grade"
  and the "contact our enterprise team" CTAs. The shared governance
  snippet is now "3. Set Up Governance", which also fixes the 23
  previously broken #3-enterprise-governance links on 14 library pages
- Air-gapped: every mention, including air-gapped-only changelog items
  (the v1.11.11 entry had nothing else and is gone)
- Portkey support: every support.portkey.ai / "Portkey support" link and
  the empty Support / Still stuck sections they leave behind

Kept: other vendors' tiers (Cursor, Atlassian, Figma, Tavily), the
reader's own customer tiers in routing examples, functional identifiers
(helm/enterprise, AirsGwEnterpriseRole, enterprise-offering paths) and
the "Enterprise Gateway" component name in the changelogs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved documentation consistency and activation-path issues remain.

Review effort: Lite
Findings: 2 Low severity

Open (2)

Comment thread aigw/integrations/llms/suggest-a-new-integration.mdx
Comment thread aigw/product/enterprise-offering/otel/analytics.mdx
…ey links

- Retire product/administration/configure-prompt-access-permissions
  (nav entry removed, ledger entry added, two Related cards removed)
- Remove "Debug Requests with Log Replay" from observability/logs; the
  feature is not in Prisma AIRS
- Remove budget-policies Use Case 9 (prompt-specific budget) and
  renumber 10-20 to 9-19
- Remove the community.portkey.ai card from Strands
- Replace app.portkey.ai dashboard links in the governance snippet with
  Strata Cloud Manager
- Agno page said "Cline" in two copy-pasted lines

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 28, 2026 09:51
@vrv-panw vrv-panw changed the title docs(aigw): MCP OAuth in SCM needs 2.22.0, and what "Error Code: 03" during registration means docs(aigw): remove content that isn't true for Prisma AIRS, plus MCP OAuth 2.22.0 and Error Code 03 fixes Sep 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

One or more issues must be addressed before approval.

Review effort: Lite
Findings: 2 Low severity

Open (2)

The registry is served by the MCP Gateway at mcp-aigw.portkey.ai, not
under aigw.portkey.ai/m. Also restore the x-portkey-api-key header in
the examples; the page's own note says Bearer isn't accepted here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved moderate documentation issues remain, including broken links, incomplete guidance, and inconsistent feature references.

Review effort: Lite
Findings: 2 Low severity

Open (2)

vrv-panw and others added 2 commits October 1, 2026 16:12
Drop the aigw/changelog copies of Enterprise Gateway and Data Service.
The Prisma AIRS Changelog tab keeps its nav but now lists
changelog/enterprise and changelog/data-service, and in-page links
follow. Redirects cover the live /aigw/changelog/* URLs, and the
retirement ledger records both pages for the nav parity check.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
No page should set a mode. Strips mode: "wide" and mode: "center"
from the twelve pages that carried it; mode keys inside code samples
are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

One or more issues must be addressed before approval.

Review effort: Lite
Findings: None

Resolved since last review (2)

@vrv-panw
vrv-panw merged commit 5b8f126 into main Oct 1, 2026
4 checks passed

This branch was successfully deployed

1 active deployment
staging — 59b00f6b Deployed Oct 1, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants