Kong gives every Dev Portal an MCP server, and the catalog lost track of Kong's

Kong gives every Dev Portal an MCP server, and the catalog lost track of Kong's

Kong has shipped the piece that turns a developer portal into something an agent can read without scraping it. In Kong Introduces the Portal MCP Server for Developer Portal, Amit Shah, Jason Harmon, and Nathanael Shermett describe a dedicated MCP server for every Konnect Dev Portal, turned on with a single toggle, that lets an agent discover and read the portal’s pages and API specs. The access model is the sentence worth keeping: “An anonymous agent sees exactly what an anonymous developer would see. An authenticated agent is bound to the same role-based permissions as the human it’s acting on behalf of.” Alongside it come OAuth 2.0 connections, an authorization-code flow with PKCE and automatic endpoint discovery, with the administrator choosing trusted clients, an allow-list of dynamic client registration redirect URLs, or both.

There are no adoption figures, and the release is honest that it builds on things already shipped: any portal page as Markdown through an Accept: text/markdown header or a .md suffix, the Konnect MCP server now able to create and publish portal pages under PAT and SPAT permissions, and the Dev Portal Toolkit generally available as a VS Code extension. The framing is the one this catalog has argued for: “This isn’t a new access model bolted onto Dev Portal, it’s the same governance you already trust, extended to a new kind of consumer.” The portal was always the machine-readable description of an API program. Kong has made it readable by the machine.

The catalog holds Kong’s surface in depth and has a gap of its own to report. The Kong provider page lists 139 API pages, and the release lands on the portal management surface: the Kong Portal Auth Settings API, where OAuth connections are configured, the Kong Portal Developers API, and the Kong Portal Audit Logs API, which is where an agent’s reads will show up next to a developer’s. The agentic access profile maps 1,242 operations, 782 of them acting and 122 flagged human-in-the-loop. On the Agent Readiness score, delegated identity and protected resource metadata are now lit. The MCP server dimension is not. Two weeks ago it was.

The Kin Score is 73.2, exemplar band, carried by access clarity at 92.1 and contract quality at 67.6, with developer ergonomics at 62.5 and contract governance at 45.5. The Agent Readiness score is 46.9, agent-ready. The unlit MCP server is the finding, and it is about us as much as Kong: a probe that found Kong’s server in September and cannot find it in October has either lost a pointer or watched one move, and a catalog that scores a company for shipping MCP servers to every portal while recording none for the company itself is wrong one way or the other. That is filed. Kong has extended the portal’s governance to a new kind of consumer. The catalog’s job is to be a consumer that can find the door, and this week it could not.

← Instrumentl's only public API is an MCP server, with eleven write tools and no contract
Retool says the CLI is you under the sink, and MCP is the chat window →