The MCP Global Access Control policy is applied to allowlist certain tools/list and tools/call in an MCP Instance under API Manager, however, this blocks the resources/read as seen in the error below.
{
"jsonrpc": "2.0",
"id": 7,
"error": {
"code": -32008,
"message": "Unable to access",
"data": "Access denied to: ui://business-groups/app.html"
}
}
The MCP Global Access Control policy, by design, enforces Allow/Block rules on various resource types, including resources/read, prompts/get, tools/list, and tools/call. It also filters responses for resources/list and prompts/list. User interface (UI) elements are categorized as resources and are therefore subject to these access control rules. If your policy does not include an explicit Allow rule for ui:// patterns, these UI elements will be implicitly blocked, leading to errors or unexpected behavior in your application's user interface.
To resolve this, configure your MCP Global Access Control policy to explicitly allow ui:// patterns.
Allow rule for the pattern ^ui://.*$.005390320

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.