AI and integrations
Connectors
Add remote MCP servers once, and their tools become available through the platform's MCP server.
A connector is a remote MCP server registered for your organization. Your MCP clients connect only to the platform's MCP server; the connector's tools appear there next to the platform's own, and the connector's credential stays on the platform.
Add a connector
Cloud → Connectors → Add connector (needs connectors:write, which owners and admins have):
| Field | |
|---|---|
| Name | Shown in Cloud and in tool titles. Up to 64 characters. |
| Slug | The prefix of its tools' names: up to 24 lowercase letters, digits and dashes, starting with a letter. Unique in the organization; can't be changed. |
| URL | The server's endpoint. https only, without credentials in the URL, and every address the hostname resolves to must be public. |
| Transport | Streamable HTTP (current servers) or HTTP+SSE (older servers: an event stream at the URL that names the endpoint to post to, which must be on the same origin). Can't be changed later. |
| Authentication | None, Bearer token (sent as Authorization: Bearer …), Custom header (a header name of your choice, such as X-API-Key) or Sign in (OAuth). |
| Token or header value | The credential: printable characters, up to 4,096. Encrypted when saved and never shown again. |
An organization can have up to 50 connectors by default (its plan can allow another number). Adding one also tests it.
Sign in (OAuth)
For servers that sign users in, as the MCP authorization spec describes. After Add and sign in, Cloud sends you to the server's sign-in page and back:
- The platform finds the server's authorization server: from the
resource_metadatain its401, its/.well-known/oauth-protected-resource, or (older servers) its own origin, and reads that server's metadata. - It registers itself as a client there (dynamic client registration) with
<cloud>/integrations/connectors/callbackas the redirect. For servers that don't allow that, enter a client ID (and secret, if it has one) from the server's developer settings when you add the connector, with that redirect URI registered. - You sign in and approve; the platform exchanges the code (PKCE
S256, with the server asresource) and lists the tools with the new sign-in.
The access and refresh tokens are encrypted like other credentials and renewed shortly before they expire. If the server refuses the refresh token, the connector shows Sign in again; use it from the connector's menu. Tool calls run with the sign-in of whoever connected it, for everyone in the organization who can use the connector's tools.
Test it
Test connects to the server, lists its tools and caches them on the connector; the status becomes OK or Error with the reason. The platform doesn't poll connectors: the MCP server offers the tools from the last successful test, so test again after the server's tools change. A failed test keeps the last good tool list.
Each connector caches up to 100 tools. Descriptions are cut at 2,000 characters, a tool that takes more than 32 KB to describe is skipped, and the list as a whole is capped at 300 KB. The connector's page shows each tool with the name it has on the MCP server.
Manage connectors
- Enable or disable with the switch: a disabled connector's tools disappear from the MCP server.
- Rotate credential replaces the token or header value; the status returns to Not checked until the next test. OAuth connectors have Sign in again instead.
- Delete removes the connector and its tools.
The URL, slug, transport and authentication type can't be changed; delete the connector and add it again.
Use its tools
An MCP client (key or OAuth sign-in) with connectors:read gets:
connectors_list: each connector's name, slug, host, whether it's enabled, its status and the tool names it adds.- Every enabled connector's tools, as
<slug>__<tool>(naming), up to 200 across connectors by default (the organization's plan can allow another number).
Calling one opens a short-lived session to the connector with its credential, calls the tool and returns its content as is, including isError. A call has 30 seconds. Failures (an unreachable server, a rejected credential, a timeout) come back as an error result naming the connector.
Security
- Credentials are encrypted with a KMS key bound to the organization and connector, and are never returned by Cloud or the API.
- The URL is checked when it's saved and again on every connection:
httpsonly, and the hostname must resolve only to public addresses (no loopback, private, link-local, carrier-grade NAT, multicast or reserved ranges), so a DNS change can't point a connector at internal hosts. - Redirects aren't followed, and responses are capped at 4 MB.
- Adding, changing, signing in to and deleting connectors is recorded in the audit log, and so is every tool call (tool name, outcome and duration; never arguments or results).