What Is an MCP Registry, and Do You Need a Private One?
An MCP registry is a catalog of MCP servers that lists each server's name, where to find it, and how to run it. The official MCP Registry, which its documentation describes as in preview, stores metadata only and does not host code or accept private servers. You need a private registry when you have internal servers or want employees to use only approved ones. Metorial provides this through portals that publish approved integrations to groups.
There are thousands of MCP servers, and nothing in the protocol says which ones are real, current, or approved for your company. A registry is the catalog that answers the first two questions. The third one you answer yourself.
What is an MCP registry?
A registry is a directory of MCP servers. Each entry records metadata, not the server itself: its name, a description, where to get it, and how to run it.
The official MCP Registry stores each entry in a file format called server.json. It holds a unique name such as io.github.user/server-name, the location of the server (an npm package name or a remote URL), execution details such as arguments and environment variables, and discovery data such as a description and capabilities.
What does the official registry cover, and what does it not?
Its documentation describes it as the centralized metadata repository for publicly accessible servers, and says it is currently in preview, so details may change.
It hosts metadata, not code. The code lives in package registries such as npm, PyPI, and Docker Hub, and the registry maps a server name to a package there.
It verifies namespaces. Names use reverse DNS (domain name system) form, so only the owner of a GitHub account or a domain can publish under it.
It delegates security scanning to the package registries and to downstream aggregators, so a listing proves who published the server, not that the code is safe.
It does not support private servers, and it is intended to be consumed by marketplaces rather than directly by host applications.
How is a registry different from a marketplace or a gateway?
A marketplace is typically a downstream aggregator. It pulls registry data and adds curation, ratings, or extra metadata. A registry and a marketplace both help you find a server. Neither stands in the call path.
A gateway does stand in the path. It decides who may call which tool, runs the sign-in, and records the call. The question "which servers exist and are approved?" is a catalog question. "Who just called what?" is a gateway question. See What is an MCP gateway? and, for public options, best MCP registries and marketplaces.
Do you need a private one?
Probably yes if any of these is true: you run internal servers that cannot be published publicly, you want employees to pick from an approved list instead of installing whatever they find, or a security team needs to review each server before it is used.
Probably not if you are one developer connecting a few public servers directly.
You can build a private registry. The official documentation says private registries can implement the same OpenAPI interface as the public one, which lets host applications that support it read your catalog. What you take on is the work around the list: reviewing entries, keeping them current, and deciding who sees what.
What should a private registry record about each server?
The public format covers name, location, and how to run it. A company catalog usually needs more, because the entry is also an approval record.
Useful fields are who owns the server internally, where the source or vendor documentation lives, which version was reviewed and when, which tools it exposes, which credentials or scopes it needs, and which teams may use it. Without the reviewed version, an approval silently covers every later release. Without an owner, nobody can answer a question about the server when it misbehaves.
Remove entries as deliberately as you add them. A catalog that still lists a server nobody maintains gives people a reason to install it.
What does it look like in Metorial?
Metorial does this job through portals. An admin creates a portal for a team, publishes the integrations that team may use, and sets access groups to allow or deny each one. People sign in and see only what their group allows.
The catalog starts from 1,000+ integrations and can include remote and custom MCP servers your company already runs. Each portal listing is either user-configured, where each person connects their own credentials, or pre-configured, where administrators manage shared credentials. Details are in the portals documentation.
Version pinning holds an integration at the version you reviewed, and schema change monitoring flags when a provider changes its tools.
Frequently asked questions
Does the official MCP Registry host server code?
No. It hosts metadata that points to packages on registries such as npm, PyPI, and Docker Hub, or to a public remote server URL. The code stays where the publisher put it.
Does the registry check that a server is safe?
It verifies who owns a namespace, through GitHub, DNS (domain name system), or an HTTP challenge. It delegates security scanning to the underlying package registries and to downstream marketplaces. Verified ownership is not a security review of the code.
Can I publish an internal MCP server to the official registry?
No. The registry does not support private servers, meaning servers reachable only on a private network or installed from a private package registry. Its documentation recommends hosting your own private registry for those.
Can I self-host the official registry?
The documentation says the official codebase is not designed for self-hosting and the maintainers cannot support it. A private registry can instead implement the same OpenAPI interface, so host applications that understand it can use your registry too.
Is a registry the same as a marketplace or a gateway?
No. A registry lists servers. A marketplace is usually built on registry data and adds curation or ratings. A gateway sits in the call path and enforces sign-in, access, and logging. Many companies use a registry or catalog together with a gateway.