mcp service command group manages AgentKit MCP services. An MCP service deploys a containerized MCP server as an AgentKit cloud resource with network and authentication settings. The current release supports listing, inspecting, creating, and deleting services. Creation supports only the custom-private backend and the MCP protocol.
Sign in to the target provider with permissions to manage MCP services, pull images, and use the selected gateway. Image URLs below illustrate the format; replace them with uploaded, pullable images. For BytePlus, use --provider byteplus with its region and registry
Command overview
mcp service list
List MCP services in a project. When no region is specified, the CLI detects the region automatically. Use--json to return raw JSON for scripts.
mcp service show
Show an MCP service’s status, backend type, protocol, access path, project, and tags.<service> can be a service name or ID. A name must be unique within the project.
mcp service create
Create an MCP service from a container image. Before starting, prepare an image that AgentKit can pull and make sure its startup command runs the MCP server. On success, the command prints the service name and ID.Only the
custom-private backend and mcp protocol are currently available. --backend-type recognizes reserved values for other backends, but creation rejects backends that are not yet supported.
The following example creates a public service with inbound API key authentication:
Configure networking
Thepublic mode cannot be combined with a VPC or subnet. Both private and hybrid require --vpc-id and --subnet-id; hybrid enables public and private access.
Configure custom JWT
Withcustom-jwt, provide an OIDC discovery URL and at least one allowed client ID. Do not pass API key flags in the same command.
mcp service delete
Exclusive gateways
Exclusive mode requires an existing gateway instance and inherits its network. Do not combine it with private or hybrid--network, --vpc-id, or --subnet-id. Shared mode rejects --gateway-instance-id and --backend-access-type
agentkit mcp service show internal-tools to verify gateway and backend access settings
After the create request succeeds, use mcp service show to inspect state and the access address, then verify tool discovery and a call from the client. If a ready service rejects calls, distinguish its inbound API key/JWT from outbound credentials used by tools to access external systems