Full Portkey Admin API MCP server — configs, prompts, keys, analytics, and more.
Portkey Admin MCP Server (io.github.s-b-e-n-s-o-n/portkey-admin-mcp)
This Model Context Protocol (MCP) server exposes the Portkey Admin API as an MCP server. It provides multiple administrative capabilities across prompts, configs, keys, analytics, governance, and deployments, supported by 178 tools, and is implemented using TypeScript.
🛠️ Key Features
Portkey Admin API surfaced via MCP
178 tools covering prompts, configs, keys, analytics, governance, deployments, and more
Topics include: admin-api, ai-gateway, llm, llmops, observability, and model-context-protocol
🚀 Use Cases
Manage Portkey resources such as prompts, configurations, and keys
Review analytics and apply governance and deployment-related administration
Integrate Portkey administration into MCP-based LLM tooling
⚡ Developer Benefits
MCP server compatibility with model-context-protocol
Tool coverage across admin domains (178 tools total)
Source data does not describe specific transport/protocol details, authentication behavior, or tool-by-tool interfaces beyond the tool count and admin scope.
The Portkey Admin API as an MCP server — 181 tools across prompts, configs, keys, analytics, governance, deployments, and more.
IMPORTANT
Active compatibility development. Palo Alto Networks completed its Portkey acquisition on 2026‑05‑29 and now presents Portkey as the core of Prisma AIRS AI Gateway. The Portkey Admin API remains live, and its official OpenAPI and product changelog continued adding control-plane surfaces through September 2026; this project has therefore resumed API-coverage work. It targets the Portkey-compatible API (x-portkey-api-key), not Prisma AIRS/Strata Cloud Manager directly. Prisma AIRS AI Gateway currently has a different management and authentication surface, so it is not a PORTKEY_BASE_URL swap. See the short Prisma AIRS interoperability guide for the supported side-by-side model and adapter criteria.
Scoping domains is also the biggest lever on context cost, not just access. tools/list
is paginated, and the complete 181-tool catalog is roughly 400 KB once a
client follows nextCursor through every page. Narrowing to the domains a client
actually needs cuts that roughly proportionally.
Build from source
bash
git clone https://github.com/CodesWhat/portkey-admin-mcp.git
cd portkey-admin-mcp
npm install && npm run build
Organize prompt versions (production, staging, dev)
Configs
6
Gateway routing, caching, retry, loadbalancing
Deployments
5
Register, inspect, update, and archive self-hosted Gateways
API Keys
6
Create, rotate, and manage scoped API keys
Secret References
5
Manage AWS, Azure, and HashiCorp external-secret references
Virtual Keys
5
Manage provider access keys
Collections
5
Group prompts by app or project
Providers
5
Manage AI provider configurations
Integrations
11
Provider integrations, model pricing, models, workspace access
MCP Integrations
10
External MCP tool integrations
MCP Servers
12
MCP server registry, capabilities, and live connections
Guardrails
14
LLM and MCP-tool policies, server mappings, organisation defaults, workspace exclusions
Usage Limits
7
Cost and token consumption limits
Rate Limits
5
Request frequency controls
Analytics
22
Cost, latency, errors, tokens, cache, feedback, provider groups
Logging
10
Log retrieval, ingestion, export, and field restrictions
Tracing
2
Feedback creation and updates on traces
Users & Workspaces
24
User management, invites, workspace members, SCIM group mappings
Audit
1
Audit log access
181 tools total across 20 tool domains. See ENDPOINTS.md for the full list with descriptions.
Portkey's newer product language increasingly presents provider credentials as
Providers, while the current Admin API still exposes both /virtual-keys and
/providers. This server keeps both domains: Virtual Keys manage provider access
credentials, and Providers manage workspace provider configurations.
API Key Scopes
Most tools work with a workspace-scoped service key that has Select All permissions enabled. That covers prompts, configs, virtual/API keys, providers, guardrails, workspace integrations, MCP servers, rate/usage limits, logs, prompt completions, and workspace user management.
If a tool returns a 403 with Portkey error AB03, it means missing scopes — not a broken endpoint.
Enterprise-gated tools and other scope requirements
Enterprise-gated tools (53)
The following tools require an organisation-level scope that is only available on Portkey Enterprise plans. They return 403 You do not have enough permissions to execute this request on workspace plans. Their descriptions include an Enterprise-gated. Returns 403 on non-Enterprise Portkey plans. suffix so MCP clients know upfront.
Org-level service API key creation via create_api_key
organisation_service_api_keys.create (Enterprise)
HTTP Server (Experimental)
Status: The HTTP transport works locally and is covered by the integration test suite, but it is a proof of concept — there is no hosted version of this server, and hosted deployment is not currently a goal. Use stdio (npx) as the supported transport.
The server supports Streamable HTTP for remote access:
HTTP authentication controls access to the server, but it does not impersonate
separate Portkey tenants. All authenticated principals use the same configured
PORTKEY_API_KEY and can invoke any enabled tool and scope that credential
grants. Run separate instances or deployments with separately scoped Portkey
credentials and PORTKEY_TOOL_DOMAINS allowlists for different trust levels.
For local-only HTTP use, leave MCP_HOST at its default 127.0.0.1. Set MCP_HOST=0.0.0.0 only when you intentionally need to accept connections from outside the local machine, such as Docker or a reverse proxy on another interface.
Full environment variable reference
Variable
Default
Description
PORTKEY_API_KEY
(required)
Your Portkey API key
PORTKEY_BASE_URL
https://api.portkey.ai/v1
Portkey Admin API base URL. Prisma AIRS/SCM URLs are not compatible; credentialed requests never auto-follow redirects
PORTKEY_ALLOW_PRIVATE_BASE_URL
—
Set to true to allow a literal loopback/private PORTKEY_BASE_URL
PORTKEY_ALLOW_INSECURE_HTTP
—
Separately set to true only when a trusted self-hosted gateway cannot use HTTPS
PORTKEY_TOOL_DOMAINS
—
Server-side allowlist of the 20 domains: users, workspaces, configs, deployments, keys, collections, prompts, analytics, guardrails, limits, audit, labels, partials, tracing, logging, providers, secret-references, integrations, mcp-integrations, mcp-servers. HTTP ?tools= may narrow it but cannot expand it
MCP_HOST
127.0.0.1
Bind address
MCP_PORT
3000
Port
MCP_PUBLIC_BASE_URL
—
Public absolute base URL to advertise from /auth/info and the status page; recommended for hosted deployments
MCP_AUTH_MODE
none
none, bearer, or clerk (none is blocked for HTTP unless explicitly overridden)
MCP_AUTH_TOKEN
—
Secret for bearer auth
CLERK_ISSUER / CLERK_AUDIENCE
—
Required issuer and audience when MCP_AUTH_MODE=clerk
CLERK_ALLOWED_SUBJECTS
—
Optional CSV subject allowlist for Clerk; at least one Clerk authorization policy is required
Optional CSV organization and role constraints; every configured constraint must match
CLERK_REQUIRED_PERMISSIONS
—
Optional CSV permissions that must all be present in the verified Clerk JWT
MCP_ALLOW_UNAUTHENTICATED_HTTP
—
Set to true only for intentional local unauthenticated HTTP debugging
MCP_SESSION_MODE
stateful
stateful or stateless
MCP_MAX_SESSIONS
100
Maximum concurrent stateful sessions or active stateless request handlers
MCP_EVENT_STORE
off
off, memory, or redis; stateless GET /mcp replay requires memory or redis
MCP_EVENT_TTL_SECONDS
300
Replay retention in seconds
MCP_EVENT_STORE_MAX_EVENTS
10000
Maximum events retained by the in-memory replay store; oldest events are evicted first
MCP_EVENT_STORE_MAX_BYTES
67108864
Approximate maximum serialized bytes retained by the in-memory replay store
MCP_EVENT_STORE_COMMAND_TIMEOUT_MS
5000
Redis command timeout for the event store, in milliseconds; 0 disables the timeout (restores unbounded pre-v6 behavior)
MCP_REDIS_URL
—
Redis URL for shared event store; production requires rediss:// and ACL-scoped credentials
MCP_EVENT_ENCRYPTION_KEY
—
Required 32-byte base64 AES key for Redis replay payloads; generate with openssl rand -base64 32
MCP_REDIS_KEY_PREFIX
mcp:event-store
Dedicated Redis namespace for replay data
MCP_TLS_KEY_PATH
—
TLS key for native HTTPS
MCP_TLS_CERT_PATH
—
TLS cert for native HTTPS
ALLOWED_ORIGINS
—
CORS allow-list; also used to validate the Host header (DNS-rebinding protection) when MCP_AUTH_MODE=none
MCP_TRUST_PROXY
loopback
Express trust-proxy policy. Use an exact nonnegative hop count or trusted proxy subnet; true is rejected because it trusts forwarding headers from every peer
RATE_LIMIT_STORE
memory
redis for multi-instance/serverless deployments; production memory mode requires RATE_LIMIT_SINGLE_PROCESS=true
RATE_LIMIT_REDIS_URL
—
Shared limiter Redis URL, falling back to MCP_REDIS_URL/REDIS_URL; production requires rediss://
RATE_LIMIT_REDIS_KEY_PREFIX
mcp:rate-limit
Redis namespace for atomic pre-authentication IP and principal-plus-IP token buckets
RATE_LIMIT_MAX_BUCKETS
10000
Maximum local buckets in explicit memory mode before new clients share overflow capacity
Production containers must choose their rate-limit topology explicitly: set
RATE_LIMIT_STORE=redis for multi-instance deployments, or set
RATE_LIMIT_SINGLE_PROCESS=true only for a single long-lived process.
Vercel deployment
Vercel support is kept as a reference proof of concept — we do not run a hosted deployment. See docs/VERCEL_DEPLOYMENT.md if you want to self-deploy.
Key points:
Uses stateless request handling with encrypted, principal-bound Redis replay and a shared atomic Redis rate limiter
Requires Clerk or bearer auth
Leave MCP_TLS_* unset (Vercel terminates HTTPS)
Set MCP_PUBLIC_BASE_URL to your deployment URL so advertised MCP endpoints never depend on request headers
Vercel does not support WebSockets — Streamable HTTP/SSE only
npm run dev # stdio with hot reload
npm run dev:http # HTTP with hot reload
npm test# unit + contract tests
npm run test:coverage # unit + contract tests with the enforced 80% line floor
npm run test:e2e # MCP protocol tests
npm run test:http # HTTP endpoint smoke test
npm run smoke # credentialed read-only Portkey API smoke suite
npm run ci # full pipeline (lint + typecheck + coverage + build + e2e + verify)
The live smoke suite reports expected credential-scope denials and the explicitly
tracked hosted control-plane route gaps as skips. Unexpected HTTP responses,
network errors, and response-contract failures still fail the run.
The required CI and release gates measure every TypeScript source file and fail
below 80% line coverage. The current full report is 98.19% lines, 91.92%
branches, and 98.58% functions.
npm run dev:http now requires MCP_AUTH_MODE=bearer or MCP_AUTH_MODE=clerk by default. For deliberate local-only unauthenticated testing, set MCP_ALLOW_UNAUTHENTICATED_HTTP=true.
Contributions use pull requests and the checks documented in
CONTRIBUTING.md. Project decisions and maintainer roles are
documented in GOVERNANCE.md. Report vulnerabilities through
SECURITY.md, and see SECURITY-ASSURANCE.md
for the public threat model and assurance case.
Community
Questions and bug reports belong in Issues; broader discussion, ideas, and help using the server belong in Discussions.
The maintained package, registry, marketplace, and directory records are listed
in Distribution and directories. Treat the generated
tool catalog in this repository as authoritative when a third-party index lags.