Gateways
One MCP URL per gateway, in front of the servers you pick. Create as many as your plan allows.
Lanyard is one MCP URL for your agents. Behind it sit the MCP servers you choose, the tools you allow, and each person’s own sign-in to those servers. Your agent gets one endpoint and one key; you keep the choice of what it can reach.
This guide is for people using the Lanyard console. It walks through every screen.
Open Lanyard Get startedGateways
One MCP URL per gateway, in front of the servers you pick. Create as many as your plan allows.
Servers and tools
Add servers from the catalog or by URL, then tick exactly which tools agents may call.
Connected accounts
Everyone signs in to each server as themselves. Lanyard holds the token, the agent never sees it.
Keys and agent setup
Mint a key per agent, paste the ready-made config into Claude Code, Cursor, VS Code, Codex or Windsurf.
Sharing
Share a gateway with people or with a group from your identity provider, as owner or member.
Activity
Every tool call and every change, with the outcome, the caller and the key that made it.
Organization settings
Allowed server hosts, your own OAuth clients, every key in the org, and the audit log.
Plan and usage
Seats, tool calls against the allowance, rate limits, and billing.
Without one, every agent on every laptop holds its own copy of every token. Rotating a leaked token means finding each machine. Giving somebody a tool they should not have means editing a config file nobody reads.
Lanyard moves all of that to one place:
Start with Getting Started. If you already have a gateway and just want to point an agent at it, skip to Keys and agent setup.