You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A self-hosted SCM POC (AKS, CIE with Entra ID, gateway 2.21.0) couldn't get MCP OAuth 2.1 working: API-key access worked, and OAuth failed before any login page opened. Two things in the docs would have let them fix it themselves.
Changes
aigw/product/mcp-gateway/authentication/cas.mdx
New prerequisite 1: gateway 2.22.0 or later. On 2.21.0, GET /oauth/<slug>/authorize returns 500 {"status":"failure","message":"immutable"}, so the flow stops between client registration and the CAS login page. 2.22.0 fixed it (see the 2026-09-11 changelog entry).
Two troubleshooting rows: the 2.21.0 500, and the Error Code: 03 registration failure below.
aigw/help-center/mcp-gateway-troubleshooting.mdx
New section, Client registration fails with "Invalid API Key. Error Code: 03". That body comes from the AI Gateway: the MCP Gateway's /.well-known/*, /oauth/register and OPTIONS need no API key, and its own rejection is {"error":"unauthorized"} with WWW-Authenticate. The section gives three checks (discovery URLs, a test registration, the same request from inside the pod) and the fixes: MCP_GATEWAY_BASE_URL, routing every path on the MCP host to 8788 under SERVER_MODE=all, or SERVER_MODE=unified.
One paragraph on the unified-mode URL layout: servers under /m, discovery and OAuth at the root. Only the changelog mentioned this before, and it reads as if everything moves under /m.
How this was verified
Against a live self-hosted gateway (gateway_enterprise, unified mode), with no API key on any request:
Request
2.21.0
2.22.0
GET /.well-known/oauth-authorization-server
200
200
OPTIONS /oauth/register
204 + CORS
—
POST /oauth/register
201 (also 201 with a bogus Authorization or x-portkey-api-key)
201
GET /oauth/<slug>/authorize
500 immutable
200, redirect to cloud-auth.us.apps.paloaltonetworks.com
POST to a non-MCP path
401 Invalid API Key. Error Code: 03
—
Not verified: SERVER_MODE=mcp / all on 8788. The in-pod check in the new section is there to tell a routing fault from a mode-specific one.
Checks
mint validate passes. mint broken-links --check-anchors flags nothing new; the three anchors it reports on the troubleshooting page are pre-existing and also appear on the non-aigw copy.
Also in this PR: removing claims that aren't true for Prisma AIRS
Six commits, all confined to aigw/ and snippets/aigw/:
ec431c9d AWS and Azure Marketplace. Retires self-hosting/hybrid-deployments/aws/marketplace (removed from nav, recorded in the retirement ledger). Drops the Azure Marketplace note from AKS, the marketplace cards from the Integrations overview, and the marketplace, strategy-call and demo CTAs from the Azure cloud page. Repoints private-cloud links that sent readers to the Latest version.
08c782d0 Claims earlier sweeps missed: SOC 2 / ISO / GDPR / HIPAA and 99.995% uptime, "hosted on edge workers", the open-source npx @portkey-ai/gateway setup on Ollama, and the JWT "contact sales" upsell.
1dad2cdb Prompt Studio text: 41 files. The prompts.* API key scopes, prompt_id and the cache-internals rows stay, because they are identifiers.
0046b388 Plan tiers, generic enterprise copy, air-gapped and Portkey support: 143 files, air-gapped changelog items included. Vendors' own tiers, functional identifiers and the "Enterprise Gateway" component name stay. This also fixes 23 #3-enterprise-governance links on 14 library pages that were already broken.
03f84fc4 Prompt permissions, Log Replay and remaining Portkey links: retires configure-prompt-access-permissions, removes the Log Replay section and budget-policies Use Case 9 (the rest are renumbered), and removes the community.portkey.ai card. The app.portkey.ai links in the governance snippet now point at Strata Cloud Manager.
eb331f3f Registry API host: the endpoint moves from aigw.portkey.ai/m/v0.1/servers to the MCP Gateway host, mcp-aigw.portkey.ai/v0.1/servers. The examples go back to the x-portkey-api-key header, which matches the page's note that Bearer isn't accepted.
mint validate, check_nav_page_parity.py and check_anchors.py pass.
…during registration means
Two gaps a self-hosted SCM POC hit in the field:
- cas.mdx listed no minimum gateway version. On 2.21.0 GET /oauth/<slug>/authorize
returns 500 {"message":"immutable"}, so the flow dies between client registration
and the CAS login page. Added as prerequisite 1 and a troubleshooting row.
- A client reporting "Dynamic Client Registration rejected (HTTP 401)" with
"Invalid API Key. Error Code: 03" is talking to the AI Gateway, not the MCP
Gateway, whose /oauth/register takes no API key. The troubleshooting page now
says how to tell the two apart, how to confirm from inside the pod, and the
base-URL / routing / unified-mode fixes. It also notes that unified mode keeps
/.well-known and /oauth at the root while servers move under /m.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The misrouted-OAuth failure and the unified-mode URL layout apply to any
self-hosted gateway, not only Prisma AIRS. The CAS prerequisite stays
aigw-only because CAS is a Palo Alto Networks service.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses the Copilot review comment: step 1 gives /{slug}/mcp, but
unified mode serves MCP under /m. The Confirm steps probe port 8788,
which exists only with SERVER_MODE=all or mcp; start-server.ts routes
/.well-known and /oauth to the MCP app in unified mode.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Addresses the Copilot review comment: step 3 said "repeat it" but ran a
GET for discovery metadata, which can succeed while /oauth/register is
misrouted.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GET /v1/health is documented elsewhere in this repository as returning only Server is healthy, so it is a liveness check rather than a way to identify whether the running deployment is 2.21.0 or 2.22.0. Point readers to the deployed image/release tag (or a version-bearing endpoint) instead; otherwise they cannot verify this prerequisite as instructed.
The preceding confirmation steps explicitly apply to both SERVER_MODE=all and SERVER_MODE=mcp, but this fix only tells all deployments to route every path. A standalone mcp deployment can have the same host/ingress misroute and needs the same correction; include mcp here or explain its distinct routing requirement.
Prisma AIRS AI Gateway is not sold through either marketplace; every
mention pointed at Portkey's own listings.
- Retire self-hosting/hybrid-deployments/aws/marketplace (nav entry
removed, recorded in the retirement ledger)
- Drop the Azure Marketplace note from the AKS guide and both
marketplace cards from the Integrations overview
- Azure cloud page: replace the 1-click Marketplace card and step with
the AKS / ACA hybrid guides, and remove the strategy-call CTA,
Book-a-Demo iframe and unsourced "75% faster" stats
- Repoint private-cloud-deployments links that escaped to the Latest
version (mongodb, prometheus-metrics, azure) at the aigw hybrid guides
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Residue from Phases 3 and 5, which removed these claims elsewhere:
- SOC 2 / ISO 27001 / GDPR / HIPAA claims on security, audit-logs and
the Arize page, and the 99.995% uptime line
- "Hosted on edge workers" in the Welcome FAQ
- The open-source `npx @Portkey-AI/gateway` local setup on Ollama
- JWT "contact sales / add-on to your plan" upsell
- "Enterprise customers and select Pro users" and "Enterprise users"
tier gates on workspace budgets and MongoDB
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Prompt Studio and the prompt endpoints are not part of Prisma AIRS AI
Gateway (dropped in Phase 1 and upstream in the spec). Phase 1 stripped
the links; this removes the prose that still told readers to use them.
- Agent pages (7): the "Prompting in <framework>" section with its
Playground / Templates / Versioning tabs, the "Version-controlled
prompts" intro bullet, and later numbered headings renumbered
- LLM pages (12): "Managing <Provider> Prompts" sections; the
"prompt management" item dropped from 19 provider intros
- Libraries: empty Prompt Management / Prompt Templates stubs
(langchain, llama-index, vercel, openai-agent-builder x2)
- Product: prompt sections in function-calling and vision, prompt IDs
and the prompt-template Replay caveat in logs, prompt endpoints in
the guardrails capabilities tables, Prompt Playground in fine-tuning
- Prompt caching (Anthropic, Bedrock): prompt-template mentions
- Help Center: Prompt Studio and the prompt completions endpoint row
Left alone as functional identifiers or gateway internals: permission
scopes (`prompts.*`), config `prompt_id`, the budget-policy `prompt`
key, cache object types, sync payload types, KMS object list.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y support
Prisma AIRS AI Gateway has no plans or tiers, is offered as managed and
hybrid only, and is not supported through Portkey's support desk.
- Plan tiers: drop the "available on all plans" callouts (19 pages), the
guardrails tier table and "select Enterprise customers only"; reword
"self-hosted Enterprise" / "Hybrid enterprise customers" to hybrid
- Generic enterprise copy: "Enterprise Features Now Available",
"Enterprise Governance", "for enterprise customers", "enterprise-grade"
and the "contact our enterprise team" CTAs. The shared governance
snippet is now "3. Set Up Governance", which also fixes the 23
previously broken #3-enterprise-governance links on 14 library pages
- Air-gapped: every mention, including air-gapped-only changelog items
(the v1.11.11 entry had nothing else and is gone)
- Portkey support: every support.portkey.ai / "Portkey support" link and
the empty Support / Still stuck sections they leave behind
Kept: other vendors' tiers (Cursor, Atlassian, Figma, Tavily), the
reader's own customer tiers in routing examples, functional identifiers
(helm/enterprise, AirsGwEnterpriseRole, enterprise-offering paths) and
the "Enterprise Gateway" component name in the changelogs.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ey links
- Retire product/administration/configure-prompt-access-permissions
(nav entry removed, ledger entry added, two Related cards removed)
- Remove "Debug Requests with Log Replay" from observability/logs; the
feature is not in Prisma AIRS
- Remove budget-policies Use Case 9 (prompt-specific budget) and
renumber 10-20 to 9-19
- Remove the community.portkey.ai card from Strands
- Replace app.portkey.ai dashboard links in the governance snippet with
Strata Cloud Manager
- Agno page said "Cline" in two copy-pasted lines
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
vrv-panw
changed the title
docs(aigw): MCP OAuth in SCM needs 2.22.0, and what "Error Code: 03" during registration means
docs(aigw): remove content that isn't true for Prisma AIRS, plus MCP OAuth 2.22.0 and Error Code 03 fixes
Sep 28, 2026
The registry is served by the MCP Gateway at mcp-aigw.portkey.ai, not
under aigw.portkey.ai/m. Also restore the x-portkey-api-key header in
the examples; the page's own note says Bearer isn't accepted here.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Drop the aigw/changelog copies of Enterprise Gateway and Data Service.
The Prisma AIRS Changelog tab keeps its nav but now lists
changelog/enterprise and changelog/data-service, and in-page links
follow. Redirects cover the live /aigw/changelog/* URLs, and the
retirement ledger records both pages for the nav parity check.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
No page should set a mode. Strips mode: "wide" and mode: "center"
from the twelve pages that carried it; mode keys inside code samples
are unchanged.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A self-hosted SCM POC (AKS, CIE with Entra ID, gateway 2.21.0) couldn't get MCP OAuth 2.1 working: API-key access worked, and OAuth failed before any login page opened. Two things in the docs would have let them fix it themselves.
Changes
aigw/product/mcp-gateway/authentication/cas.mdxGET /oauth/<slug>/authorizereturns500 {"status":"failure","message":"immutable"}, so the flow stops between client registration and the CAS login page. 2.22.0 fixed it (see the 2026-09-11 changelog entry).Error Code: 03registration failure below.aigw/help-center/mcp-gateway-troubleshooting.mdx/.well-known/*,/oauth/registerandOPTIONSneed no API key, and its own rejection is{"error":"unauthorized"}withWWW-Authenticate. The section gives three checks (discovery URLs, a test registration, the same request from inside the pod) and the fixes:MCP_GATEWAY_BASE_URL, routing every path on the MCP host to8788underSERVER_MODE=all, orSERVER_MODE=unified./m, discovery and OAuth at the root. Only the changelog mentioned this before, and it reads as if everything moves under/m.How this was verified
Against a live self-hosted gateway (
gateway_enterprise, unified mode), with no API key on any request:GET /.well-known/oauth-authorization-serverOPTIONS /oauth/registerPOST /oauth/registerAuthorizationorx-portkey-api-key)GET /oauth/<slug>/authorizeimmutablecloud-auth.us.apps.paloaltonetworks.comInvalid API Key. Error Code: 03Not verified:
SERVER_MODE=mcp/allon8788. The in-pod check in the new section is there to tell a routing fault from a mode-specific one.Checks
mint validatepasses.mint broken-links --check-anchorsflags nothing new; the three anchors it reports on the troubleshooting page are pre-existing and also appear on the non-aigw copy.Also in this PR: removing claims that aren't true for Prisma AIRS
Six commits, all confined to
aigw/andsnippets/aigw/:ec431c9dAWS and Azure Marketplace. Retiresself-hosting/hybrid-deployments/aws/marketplace(removed from nav, recorded in the retirement ledger). Drops the Azure Marketplace note from AKS, the marketplace cards from the Integrations overview, and the marketplace, strategy-call and demo CTAs from the Azure cloud page. Repoints private-cloud links that sent readers to the Latest version.08c782d0Claims earlier sweeps missed: SOC 2 / ISO / GDPR / HIPAA and 99.995% uptime, "hosted on edge workers", the open-sourcenpx @portkey-ai/gatewaysetup on Ollama, and the JWT "contact sales" upsell.1dad2cdbPrompt Studio text: 41 files. Theprompts.*API key scopes,prompt_idand the cache-internals rows stay, because they are identifiers.0046b388Plan tiers, generic enterprise copy, air-gapped and Portkey support: 143 files, air-gapped changelog items included. Vendors' own tiers, functional identifiers and the "Enterprise Gateway" component name stay. This also fixes 23#3-enterprise-governancelinks on 14 library pages that were already broken.03f84fc4Prompt permissions, Log Replay and remaining Portkey links: retiresconfigure-prompt-access-permissions, removes the Log Replay section and budget-policies Use Case 9 (the rest are renumbered), and removes thecommunity.portkey.aicard. Theapp.portkey.ailinks in the governance snippet now point at Strata Cloud Manager.eb331f3fRegistry API host: the endpoint moves fromaigw.portkey.ai/m/v0.1/serversto the MCP Gateway host,mcp-aigw.portkey.ai/v0.1/servers. The examples go back to thex-portkey-api-keyheader, which matches the page's note that Bearer isn't accepted.mint validate,check_nav_page_parity.pyandcheck_anchors.pypass.🤖 Generated with Claude Code