Control MCP server access for your organization changedmanaged-mcp
Nearest release: v2.1.293, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 7 Oct 2026 17:15 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 7 Oct 2026 17:37 UTC.
Upstream edited
Recorded here
Lines+17added
Lines−5removed
From line
301
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits23to this page, all time
The whole hunk
from line 301, old and new numbered
/
from line 301
301301
302302#### How `serverUrl` entries match
303303
304URLs support `*` wildcards anywhere in the pattern, including the scheme. Hostname matching is case-insensitive and ignores a trailing FQDN dot, so `https://Mcp.Example.com/*` matches `https://mcp.example.com/api`. Paths stay case-sensitive.
304URLs support `*` wildcards, including `*` as the whole scheme. Hostname matching is case-insensitive and ignores a trailing FQDN dot, so `https://Mcp.Example.com/*` matches `https://mcp.example.com/api`. Paths stay case-sensitive. If you give no port, how you write the hostname decides whether the pattern matches only the scheme's default port or every port:
305305
306* **Hostname written out in full**: the default port only, 443 for `https` and 80 for `http`
307* **Hostname with a `*` in it**: every port
308
306309The table shows what common patterns allow:
307310
308311| Pattern | Allows |
309312| :- | :- |
310| `https://mcp.example.com/*` | All paths on a specific domain |
311| `https://mcp.example.com` | Also all paths on that domain. A pattern with no path matches any path |
312| `https://*.example.com/*` | Any subdomain of `example.com` |
313| `https://mcp.example.com/*` | All paths on a specific domain, on port 443 only |
314| `https://mcp.example.com` | Also all paths on that domain, on port 443 only. A pattern with no path matches any path |
315| `https://mcp.example.com:8443/*` | All paths on that domain, on port 8443 only |
316| `https://mcp.example.com:*/*` | All paths on that domain, on any port, 443 included |
317| `https://*.example.com/*` | Any subdomain of `example.com`, on any port |
313318| `http://localhost:*/*` | Any port on localhost |
314| `*://mcp.example.com/*` | Any scheme to a specific domain |
319| `*://mcp.example.com/*` | Any scheme to a specific domain, each scheme on its default port only |
315320
321Entries in `deniedMcpServers` match ports the same way, so choose an entry for `staging.example.com` by the ports and schemes you need to block:
322
323* `https://staging.example.com/*`: blocks `https` servers on that host on port 443 only, so it doesn't block a server at `https://staging.example.com:8443/api`
324* `https://staging.example.com:*/*`: blocks `https` servers on that host on every port
325* `*://staging.example.com:*/*`: blocks that host over any scheme and on any port
326
316327<h4 id="how-policy-entries-expand">
317328 Environment variables in `serverCommand` and `serverUrl` entries
318329</h4>
from line 488
477488 | :- | :- |
478489 | HTTP server at `https://mcp.example.com/api` | Allowed: matches allowlist URL pattern, no denylist match |
479490 | HTTP server at `https://staging.example.com/api` | Blocked: matches both, but the denylist takes precedence |
491 | HTTP server at `https://staging.example.com:8443/api` | Allowed: matches allowlist URL pattern, [no denylist match on this port](#how-serverurl-entries-match) |
480492 | HTTP server at `https://other.com/mcp` | Blocked: doesn't match the allowlist |
481493</Accordion>
482494
No line in this hunk matches that.