Skip to main content

Custom TLS Certificates for Enterprise MCP Integrations

Learn how to configure a custom TLS CA bundle so elvex can connect to internal MCP servers and OAuth endpoints that use private certificates.

Many enterprise organizations operate internal services behind private certificate authorities (CAs) — custom TLS certificates that aren't trusted by default by public certificate stores. When elvex tries to connect to an MCP server or OAuth endpoint that uses one of these private certificates, the connection fails with a TLS verification error, even though the certificate is valid within your organization's network.

elvex now supports configuring a custom TLS CA bundle per integration, allowing you to connect to internal MCP servers and OAuth endpoints that use private certificates.

You might need this feature when:

  • Your organization runs internal MCP servers behind a corporate proxy or private CA

  • Your OAuth provider uses a certificate signed by an internal certificate authority

  • You're connecting elvex to an on-premises service that uses a self-signed certificate

  • Your security team requires all internal services to use certificates from a company-managed CA

How It Works

A custom TLS CA bundle is a PEM-formatted certificate file that tells elvex to trust connections signed by your organization's private certificate authority. Once configured for an integration, elvex will use your CA bundle to verify TLS connections for:

  • OAuth token exchange and refresh requests

  • OAuth discovery endpoints

  • MCP server connections and tool calls

This is configured per integration, so you can apply custom certificates only to the integrations that need them, without affecting other connections.

Setting Up a Custom TLS CA Bundle

Custom TLS CA configuration is an advanced, operations-level setting. Contact your elvex administrator or elvex support to configure a custom CA bundle for a specific integration. You will need to provide:

  • The PEM-formatted CA certificate bundle for your organization

  • The name of the integration you want to configure it for

Once configured, elvex will automatically use the custom CA bundle for all TLS connections to that integration's endpoints.

Common Questions

Which integrations support custom TLS CA bundles?

Custom TLS CA bundles are currently supported for manual OAuth MCP integrations. If you need this for a different integration type, contact elvex support.

Do I need to reconfigure this if my CA certificate is renewed?

Yes. If your organization renews or rotates its CA certificate, you will need to update the CA bundle in elvex. Contact your elvex administrator to update the configuration.

Is this the same as uploading a client certificate?

No. A CA bundle tells elvex to trust servers that present certificates signed by your CA. Client certificates are used to authenticate elvex to a server. These are different configurations.

Did this answer your question?