AI Guide to the Galaxy Episode 3: From Chatbots to Agents - Docker’s MCP Toolkit & Gateway Explained
By Docker
Docker AI and the MCP Toolkit: Empowering AI Agents with Containerized Tools
This interview delves into Docker's advancements in supporting AI agents, focusing on the Model Context Protocol (MCP) and the development of the MCP Toolkit. Jim Clark, a Principal Software Engineer at Docker, shares his journey and insights into how Docker is enabling developers to build and deploy more capable AI agents.
1. Docker Labs and the Genesis of AI Agent Support
Docker Labs began exploring AI approximately a year prior to the interview, initially focusing on how Docker could assist developers building AI agents. The core idea was to empower agents beyond simple question answering, enabling them to formulate plans and strategies. This led to the concept of providing agents with tools to execute these plans.
- Key Point: The realization that AI agents could benefit from having executable tools, and that Docker containers are a natural fit for packaging and running these tools.
- Early Experiments: These experiments, predating the formal MCP specification, were informally named "labs AI tools for devs." The focus was on enabling tool-calling agents with containers as the underlying tool mechanism.
2. The Impact of the MCP Protocol and the Birth of the MCP Toolkit
The release of Anthropic's Model Context Protocol (MCP) specification served as a significant inflection point, providing a framework for discussing AI agents with agency and the capacity to influence the real world.
- MCP Protocol: A specification that allows AI models to interact with external tools and data sources.
- Docker's Connection: Jim Clark recognized that Docker's work aligned with the MCP's goals, particularly in providing context to models.
- The "Kevin Bacon" of Silicon Valley: Docker's Head of Engineering, Tashar, leveraged his extensive network to connect with the MCP spec authors.
- Mutual Need: The MCP authors identified a need for easier tool installation for MCP users, while Docker saw an opportunity to simplify MCP adoption through containerization.
- MCP Toolkit Conception: The MCP Toolkit was conceived to address the "installation problem" of using MCPs. The idea of a catalog of MCP servers mirrors the functionality of a Docker registry, simplifying the distribution and execution of these servers.
3. The MCP Toolkit: Distribution, Execution, and Security
The MCP Toolkit aims to solve the challenges of distributing and running MCP servers, offering a streamlined experience for developers.
- Distribution: The toolkit provides a catalog of MCP servers, making them discoverable and accessible.
- Execution: MCP servers are packaged as Docker containers, ensuring consistent environments and simplifying deployment. This eliminates the need for users to run potentially complex commands like
npxoruvdirectly. - Security Guarantees:
- Containerization: Running MCP servers in containers provides isolation and control over their environment (e.g., Node.js or Python versions).
- File System Access Control: Containers can be configured to limit file system access, enhancing security.
- Provenance Verification: Docker builds the container images from community-submitted GitHub repositories, ensuring provenance and allowing for verification of the build process.
- Software Bill of Materials (SBOM): Docker includes SBOMs, providing transparency into the components of the software.
- Vulnerability Scanning: Docker Scout is used for vulnerability scanning of the container images.
- Tamper Detection: The gateway performs runtime provenance verification to ensure images haven't been tampered with.
4. The MCP Toolkit in Action: Demo and Functionality
A demonstration showcased the practical application of the MCP Toolkit.
- Command-Line Interface (CLI):
docker mcp gateway run: Starts an MCP gateway server locally.docker mcp list: Lists available MCP servers in the catalog.- Adding servers like "YouTube transcript" and "Brave search" to the gateway.
- Docker Desktop Integration: A dedicated MCP Toolkit section within Docker Desktop provides a visual catalog of discoverable MCPs.
- Client Integration:
- Claude Code: Claude can be configured to connect to the MCP gateway, gaining access to available tools like "Brave local search" and "get transcript."
- VS Code: VS Code can also connect to the MCP gateway, enabling access to MCP tools within the IDE.
- Docker Compose: Agents defined in
docker-compose.yamlfiles can be configured to use the MCP gateway, allowing them to access MCP servers.
5. The MCP Registry: A Community-Driven Catalog
The MCP Toolkit relies on a community-driven open-source registry for MCP server implementations.
- Process: Developers can submit pull requests to the MCP registry GitHub project, providing a link to their public GitHub repository and Dockerfile.
- Docker's Role: Docker builds the container images from these submissions, ensuring provenance and security guarantees.
- Trusted Provider: Even if the underlying implementation comes from a hobbyist, Docker acts as a trusted provider of the built images.
6. MCP Gateway vs. MCP Toolkit
A clarification was made between the MCP Toolkit and the MCP Gateway.
- MCP Toolkit: A broader collection of tools and features within Docker Desktop and the Docker MCP CLI that facilitate the adoption, use, and building of MCPs.
- MCP Gateway: A core component of the toolkit, acting as an MCP server that aggregates and exposes other MCP servers to clients. It can be run locally via CLI or integrated into Docker Compose applications.
7. Secret Management and Security Guarantees
The MCP Toolkit incorporates features for secure handling of secrets.
- Secret Injection: Secrets can be configured in Docker Desktop or via the CLI and are securely mounted into the specific container running the MCP server at runtime.
- OAuth and Remote MCP Servers: The toolkit supports OAuth flows for authenticating with remote MCP servers. This includes dynamic OAuth discovery and dynamic client registration, enabling seamless integration with vendor-hosted MCP services.
- Security for Untrusted Servers: The secret management features protect users from inadvertently exposing sensitive information when running less-trusted MCP servers.
8. The Evolving Landscape of Remote MCP Servers
The ecosystem of remote MCP servers is rapidly expanding.
- Growth: A significant increase in the number of available remote MCP servers, beyond initial examples like Google Docs and GitHub.
- MCP Specification Adoption: Most remote MCP servers are actively implementing recommendations from the new authorization specification, including dynamic OAuth discovery and client registration.
- Accessibility: These advancements are making the ecosystem of remote MCPs more accessible.
9. Profiles and Configuration for the MCP Gateway
The concept of "profiles" is being developed to manage complex MCP server configurations.
- Versionable Configurations: Profiles allow users to define specific sets of MCP servers, tools, prompts, and resources, which can be versioned and checked into source control.
- Filtering: Users can filter tools, prompts, and resources from various MCPs to create tailored environments.
- Flexibility: Multiple gateways can be run with different profiles to cater to diverse needs (e.g., one for chess tools, another for cloud access).
- Community Collaboration: Docker is working with the community to define the best ways to create and manage these profiles.
10. Recommendations for the Community and Future Outlook
Jim Clark encourages the community to engage with the MCP Toolkit and contribute to its development.
- Explore Examples: The repository contains diverse examples of agent frameworks (A2A, ADK, Google, Agno, Crew AI, Langraph, LangChain, Embabel) that utilize the MCP Toolkit and Docker Compose.
- Build Agents: The best way to understand and utilize the MCP Gateway is by building agents with it.
- Local Development to Production: The toolkit facilitates a gradual progression from local development to production deployments, with integrations for cloud platforms like Google Cloud Run.
- Local Models: Encourages the use of local AI models to explore their sweet spots and avoid over-reliance on cloud models.
- Iterative Development: Emphasizes an iterative approach to agent development, starting locally and progressively moving towards more complex deployments.
Key Concepts
- AI Agents: Software entities capable of planning, executing tasks, and interacting with their environment.
- Model Context Protocol (MCP): A specification enabling AI models to access and utilize external tools and data.
- MCP Toolkit: A suite of Docker tools and features designed to simplify the development, deployment, and use of AI agents and MCPs.
- MCP Gateway: A core component of the MCP Toolkit that acts as an MCP server, aggregating and exposing other MCP servers to clients.
- Containerization: Packaging software and its dependencies into isolated units (containers) for consistent execution.
- Docker Registry: A repository for storing and distributing Docker images.
- Software Bill of Materials (SBOM): A list of all components and dependencies within a piece of software.
- Provenance Verification: The process of confirming the origin and integrity of software.
- OAuth: An open standard for access delegation, commonly used for authentication and authorization.
- Remote MCP Servers: MCP servers hosted by vendors or third parties, accessible via network endpoints.
- Profiles: Configurable sets of MCP servers, tools, and resources for tailored agent environments.
- Agent Frameworks: Libraries and tools that provide structures and abstractions for building AI agents.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Why Does This Guy Appear In Kids Videos?
sphynx

TIC en las Organizaciones - Electiva Complementaria II Unisimon
Julieth Güell S

How to Tame Your Advice Monster | Michael Bungay Stanier | TED
TED

Margaret Heffernan: Why it's time to forget the pecking order at work
TED

The importance of psychological safety: Amy Edmondson
The King's Fund

What Is Psychological Safety?
Harvard Business Review

13-Conflict Management: Listening in Conflict
Deliberate Development