Changing an agent or testing a server needs the organization developer or admin role. Testing a server needs the create permission, so the organization user role can’t run a test. See Organizations and roles. The server must use the Streamable HTTP transport at a public
http or https URL. Servers on private, loopback, or link-local addresses are refused. Local servers that run over stdio aren’t supported. If the server needs a token, have it ready; the token goes in a vault.About the Managed Agents MCP endpoint
About the Managed Agents MCP endpoint
On the Managed Agents MCP endpoint, operation arguments name path parameters in camelCase, such as
vaultId, while request bodies keep their snake_case fields, such as vault_id. Create skills with scripts, and read a skill version’s content, in the console or with the REST API.Add an MCP server to an agent
Each server entry has aname and a url. MCP servers belong to the agent version, so adding one creates a new version. Running sessions keep the tools they started with.
- Console
- cURL
- In the sidebar, click Agents and open the agent.
- On Configuration, find Tools and click Add MCP server.
- Enter a Server name, then choose a server from the list or type its Server URL. The list suggests common servers, such as GitHub, Notion, Linear, Sentry, Context7, and Slack, and says what kind of token each needs.
- Click Save new version.
project-tracker offers list_issues, the agent sees project-tracker__list_issues. The prefix keeps two servers from clashing. A new version replaces the whole definition, so send skills, tool settings, vault defaults, and every other field you want to keep. See Agents. Next, authenticate the server.
Server entry fields
Server entry fields
Authenticate the server
Store the server’s token in a vault as a Token for an MCP server (bearer_token) whose server URL matches the agent’s url. Then grant the vault to the agent with default_vault_ids, or to a session with vault_ids. If you narrow grants with credential refs, include this credential.
Tokens that you paste are stored as-is and aren’t refreshed. If the server issues short-lived OAuth access tokens, rotate the credential before it expires.
How matching works
How matching works
- URLs match after lowercasing the scheme and host, dropping a default port (
:443or:80), and ignoring a trailing slash. A different path, subdomain, or port is a different server, so the token isn’t sent there. - The token is sent as
Authorization: Bearer <token>by default. If the credential setssecret_name(API only), the token is sent as-is in a header with that name instead, for servers that read a header such asX-Api-Key. - If two granted vaults hold a token for the same server, the vault listed first in the session’s grants wins.
- If no token matches, the session connects without one. That works for public servers and fails for servers that need authorization.
Test a server before you use it
probeMcpServer makes one live connection using the same URL matching and vault lookup as a session. It creates and changes nothing, but it needs the Developer or Admin role, like creating resources. See Organizations and roles. Omit vault_ids to test without a token.
- Console
- cURL
- In the sidebar, click Credential vaults and open the vault.
- Expand the server’s Token for an MCP server row. It shows whether the server is reachable and how many tools it offers.
- Click Test again to run a new test.
200. Read the body:
What success means: a passing test proves the server is reachable and that the token lets you list tools. It doesn’t prove that every tool call will succeed; permissions, arguments, and the server’s own state still matter.
Every test response field
Every test response field
A test gives up after 15 seconds. A server on a private, loopback, or link-local address is refused before anything is sent, so the test returns
reachable: false with the reason in error.How a session uses an MCP server
- When a session starts, it reads the MCP servers on its agent version.
- For each server, it looks for a Token for an MCP server in the session’s granted vaults whose server URL matches.
- It connects, lists the server’s tools, and fixes that list and the tool schemas for the whole session.
- The agent calls a tool as
<server name>__<tool name>. The token is attached to every call outside the sandbox.
Choose which tools an agent gets
A session receives every tool the server lists for its token. You can’t hide individual tools of a server. To limit what an agent can do, give it a token whose scopes allow only what it needs, or point it at a server that offers fewer tools.What happens when a server fails
- At session start: an unreachable server or rejected token doesn’t stop the session. Other servers still load, and the session’s events record a warning naming the servers:
mcp_auth_rejectedwhen a server refused the token, andmcp_discovery_failedfor any other failure. Fix the token, or the URL or server, then start a new session. Running sessions don’t rediscover tools. - During a call: each request to the server has a 60-second timeout, and a response can be at most 8 MiB. A failed call returns an error to the agent as the tool result, and the agent can decide what to do next.
What can go wrong
The most common problems:- A session has an
mcp_auth_rejectedwarning. The server refused the token with401or403. Check or rotate the token in the vault, then start a new session. - A session has an
mcp_discovery_failedwarning. The server was unreachable, failed the handshake, or is on a private address. Run a test with the same URL and vault, fix the cause, and start a new session. - Unexpected
vault-...tools appear. A granted vault holds a token for an MCP server the agent doesn’t list. Remove the credential from the session’s grants, or add the server to the agent with a name you choose.
Every MCP server problem
Every MCP server problem
Next steps
Vaults and credentials
Store tokens for MCP servers and control which sessions receive them.
Agents
Publish a new agent version with its MCP servers attached.
Tools
See the built-in tools every session can use.
Events
Read discovery warnings and MCP tool calls in the session timeline.