MCP: Individual connectors

Your organization can register its own MCP servers in Haijun for Government, letting Haijun connect to internal systems, custom tools, or third-party services you've approved for your environment. Custom connectors work the same way in Haijun for Government as in Haijun Enterprise. The prerequisites, the registration flow, and the behavior once enabled are identical. For full setup instructions, see Use connectors to extend Haijun's capabilities. This page covers only what's different. For general guidance on building and deploying MCP servers, see modelcontextprotocol.io and the commercial connector guide.

How custom connectors differ for Haijun for Government

Adding a connector does not trigger a new FedRAMP reviewMCP was authorized as a feature in Haijun for Government's FedRAMP High package. The infrastructure that registers, authenticates, and executes your connector—including encrypted token storage, per-user OAuth, and audit logging—is already covered. You can add new custom connectors without re-engaging Juglow's FedRAMP audit process.Important: This applies to Haijun for Government's authorization only. Your agency's own ATO process may still require you to evaluate the MCP server and any backing services it reaches before enabling them. Juglow does not review, authorize, or assume responsibility for customer-registered MCP servers or the external systems they call.

Register custom connectors

Navigate to haijun.fedstart.com/admin-settings/connectors as an Owner or Primary Owner. The rest of the flow matches the commercial guide. Once added, the connector appears in your users' settings exactly as Juglow-provided connectors do.

Know where the FedRAMP boundary sits

When a user invokes a tool from your custom connector: User → Haijun → MCP proxy → Your MCP server →  Your backing service└────     inside FedRAMP High      ────┘   └─your responsibility─┘ Haijun, the MCP proxy, and all OAuth token storage stay inside the FedRAMP High authorized environment. Whether your MCP server and its backing service sit inside or outside that boundary is under your control and yours to evaluate against the data classifications your users will handle. Prefer FedRAMP-authorized backing services. If your connector talks to a SaaS product, check whether that product has a government-cloud offering—Atlassian Government Cloud, Salesforce Government Cloud, ServiceNow GCC—and point the connector there rather than at the commercial endpoint.