Known limits
Choices and gaps to know before you deploy Studio.
On this page
- Master key in an environment variable. A
KeyProvider(KMS, HSM) can be plugged in from code, but the CLI reads the environment only. - API keys, not OAuth. The gateway authenticates with per-server API keys. OAuth 2.1 with protected resource metadata, as the MCP authorization spec describes, is future work.
- One process. Rate limits and the gateway’s registries are in memory, so Studio does not run as several instances.
- No sub-path. Studio must be served at the root of its origin.
- Users can be deactivated, not deleted. Their audit records stay attributed to them.
Also worth knowing
- 2025-era HTTP clients get no push. Studio serves them statelessly, so they do not receive
list_changed; they see a publish on their nexttools/list. Clients on MCP 2026-07-28 that listen get it at once. - The audit page shows the latest 100 entries. Older rows stay in the database.
- Windows file permissions are not set by Studio: keep the data directory where only the Studio user can read it.
- Spec tools need https and public addresses. There is deliberately no setting that lets them reach private or loopback addresses.
The threat model lists the accepted security limits.