Known limits

Choices and gaps to know before you deploy Studio.

On this page
  • Master key in an environment variable. A KeyProvider (KMS, HSM) can be plugged in from code, but the CLI reads the environment only.
  • API keys, not OAuth. The gateway authenticates with per-server API keys. OAuth 2.1 with protected resource metadata, as the MCP authorization spec describes, is future work.
  • One process. Rate limits and the gateway’s registries are in memory, so Studio does not run as several instances.
  • No sub-path. Studio must be served at the root of its origin.
  • Users can be deactivated, not deleted. Their audit records stay attributed to them.

Also worth knowing

  • 2025-era HTTP clients get no push. Studio serves them statelessly, so they do not receive list_changed; they see a publish on their next tools/list. Clients on MCP 2026-07-28 that listen get it at once.
  • The audit page shows the latest 100 entries. Older rows stay in the database.
  • Windows file permissions are not set by Studio: keep the data directory where only the Studio user can read it.
  • Spec tools need https and public addresses. There is deliberately no setting that lets them reach private or loopback addresses.

The threat model lists the accepted security limits.