Before you connect#
Choose a server whose transport/authentication behavior matches the supported implementation. Obtain the exact process command/arguments or HTTP URL from that server's maintainer. Do not put credentials in chat messages.
Administrator-owned profiles#
Use MCP administration to create or update a server definition. Verified fields include the server ID/display name, transport, command/arguments/environment for STDIO, or URL/headers for HTTP; read-only mode, timeout and authentication mode are also configurable.
| API field | Verified use |
|---|---|
id, name | Server identity and display name |
transport | stdio or HTTP configuration |
command, args_json, env_json | Process command, arguments and environment |
url, headers_json | HTTP address and configured headers |
auth_mode | shared or per_user; STDIO forces shared |
read_only | Operator assertion used for risk/approval metadata |
timeout_seconds | Save validation accepts 1..900 seconds |
oauth_client_id | Configured pre-registered OAuth client identity |
Secret field definitions are partly redacted in the audited snapshot. Exact header/credential values must come from the server's own configuration, not examples invented here.
Test discovery#
The connection test initializes/lists tools without invoking them. Inspect returned discovery/authentication errors. Saving/deleting profiles rebuilds the runtime; startup discovery must succeed for descriptors to enter the registry.
Complete OAuth when required#
The supported OAuth flow uses authorization-code exchange and PKCE. Pre-registered OAuth is supported alongside dynamic registration where the provider permits it. Client ID Metadata Document support is detected but rejected with guidance to use pre-registration.
For per_user HTTP profiles, users connect their own identity from personal connection cards. Profiles remain administrator-owned; personal independent server definitions and personal STDIO processes are not implemented.
Configure access#
Discovered tools receive dynamic permissions. Use MCP tool permissions to configure role effects before relying on execution access.
Current implementation notes#
See the MCP API category for the exact server, test, registry and OAuth routes.