This manual is for administrators responsible for deployment, service integration, user permissions, approvals, and operations. Employees connecting tools through Codex, Claude Code, or VS Code should read the user guide.

First deployment

Start with a read-only call

Start MCPHub, initialize the administrator locally, sign in to the console, add a read-only service with its own credentials, test the connection, then publish tools and configure a test user. Complete login and client authorization. Once this works, enable writes gradually.

Install and start →

Find your administration task

Recommended deployment order

  1. Install the gateway, choose local or remote administration, and retain the database and keys.
  2. Configure HTTPS and initialize the built-in administrator, then verify administrator and ordinary user login separately.
  3. Connect a service test its connection, and explicitly publish reviewed read-only tools through tool permissions.
  4. Grant group permissions and add users, enable client authorization, and share the user guide.
  5. Configure Vault when personal business accounts are needed, and approvals when write tools are needed.
  6. Verify a real ordinary-user call, revocation, and any required approval. Follow Operations to arrange health checks, backups, and diagnostics.

Assign three administration responsibilities

RoleMain responsibility
Configuration administratorConnect services, publish tools, configure access, and inspect diagnostics.
Write reviewerReview the specific operation, target, arguments, and preview. Complete independent review as required by policy.
Security reviewerReview configuration proposals; approve and apply changes when configuration approval is enabled.
Keep production deployments to one active instanceMCPHub v2.4.0 supports SQLite or single-instance PostgreSQL. Sharing PostgreSQL does not synchronize runtime configuration across multiple gateways. Administrator access also does not automatically grant business tool access or write approval permissions.

Documentation and acceptance checks

The configuration and operations chapters come directly from the repository's administrator manual, deployment guide, SSO, Vault, and configuration reference. Replace example domains and accounts with actual values. Passing validate, a health check, or template startup does not establish that identity, account, and approval integrations work. Check your actual environment using deployment verification.