MCP servers: give the AI agent tools from other systems
What MCP servers do
MCP (Model Context Protocol) is an open standard that lets an AI use tools in another system. Under MCP servers you connect another system's MCP server to the Enydea AI agent. The agent can then look things up, or act, in that system, but only with the tools a company admin switches on.
This is the opposite direction of the Enydea connector. With the connector, Claude or ChatGPT work with your Enydea data. With MCP servers, Enydea's own agent works with another system. For the connector, see AI assistant connector.
Note: The MCP servers card is in English only, also in the Dutch, German and French app.
Before you start
- You must be a company admin. Anyone else sees Only company admins can manage MCP servers.
- The server must speak MCP over HTTP (the Streamable HTTP transport) at a public
https://address. A server that runs on your own computer or on a private network cannot be connected. - If the server needs a key, get an API key or token from its provider. Servers that only accept a sign-in through a browser page (OAuth) are not supported.
Add a server
- Open Settings -> Integrations and scroll down to MCP servers. Select Add MCP server.
- Fill in Connect an MCP server:
- Name: a name you recognise. The short name Enydea makes from it must be unique in your company.
- Server URL (https): the address the provider gives you.
- Authentication: Bearer token (the default, sent as an
Authorization: Bearerheader), Custom header with a Header name such asX-API-Key, or None. - Token / API key, unless you chose None. It is stored encrypted and never shown again.
- Max calls per agent run: 1 to 100, default 20.
- Select Connect. Enydea lists the server's tools at once, all switched off, and a message says how many it found. If the list fails, the message gives the reason and the server shows an error line.
Choose what the agent may use
Open the server's panel. Each tool shows its name, description, inputs and a policy:
| Policy | What it means |
|---|---|
| Off | The agent does not see the tool. Every tool starts here. |
| Allowed | The agent calls the tool whenever its task needs it. |
| Ask to confirm | The tool refuses until the agent calls it again with an approval flag. The agent is told to ask you first. |
Badges help you decide. read-only and can change/delete come from the server. acts (by name) means the server labels nothing, but the name starts with a word such as create, delete or send. Setting a tool that acts, by label or by name, to Allowed asks you to confirm first.
- Allow read-only tools sets the tools the server marks read-only to Allowed. If the server marks none, it allows the tools whose names do not look like they act.
- Allow all switches every tool on after you confirm: tools that act get Ask to confirm, lookups get Allowed.
- Turn all off switches every tool off.
- Filter tools searches the list. A tool that is on shows the name the agent uses:
mcp__<short name>__<tool>.
Manage a server
The panel header shows a status icon and how many tools are on.
- Enabled takes the whole server away from the agent, or gives it back, without changing the tool settings.
- Refresh tools lists the tools again. New tools start Off. A tool that was on and whose description or inputs changed is switched off and marked changed — review, so a server cannot quietly change what an allowed tool does. Choosing a policy clears the mark. Enydea does not look for changes by itself.
- Authentication in the panel changes the mode, the Header name and the token (Replace token). Select Save authentication. Choosing None deletes the stored token.
- Remove deletes the server after you confirm.
The panel cannot change the URL, the name or the call limit. Remove the server and add it again.
Call log
Opening a server's panel loads Recent calls: the last 100 calls, newest first, with the time, the tool, the result (ok, error or refused), the duration, and the error or the arguments that were sent. A call is refused when the tool is off, when the arguments do not match the tool's inputs, or when the run reached the call limit. To see new calls, close the panel and open it again.
How the agent uses the tools
- The tools work in AGENT mode of the AI Assistant and in scheduled AI Agents tasks, for everyone in your company; there is no per-person setting. CHAT mode does not use them. See AI Assistant and AI Agents.
- Claude or ChatGPT connected through the Enydea connector do not see these tools. They reach them only by handing a task to Enydea's agent.
- Enydea checks the arguments against the tool's inputs before each call. The call limit counts per server, per run.
- Results come back as data. In JSON results Enydea drops empty values, shortens long texts and summarises long lists. The agent gets at most about 8,000 characters of each result, and only text: images are left out. It is told never to follow instructions inside a result.
Confirmations
Ask to confirm is a rule for the agent, not a button. AGENT mode and scheduled tasks show no confirmation card, so the agent sets the approval flag itself after asking. Each AGENT message starts a new run that does not see your earlier messages: to approve, repeat the request and say that you approve it. A scheduled task has nobody to ask. Set a tool to Off if the agent must never use it.
Security
- Only public
https://addresses are accepted. Addresses that lead to private, local or cloud-internal networks are refused when you save and again on every connection. Redirects are not followed. A call times out after 30 seconds, and an answer over 2 MB makes it fail. - What the agent passes as arguments is sent to the other system. The agent is told to pass only what the task needs and never credentials. Connect servers you trust and allow only the tools you need.
- Nobody can read the stored token back, admins included.
Limits
- Enydea keeps the first 300 tools of a server.
- The agent cannot call a tool whose name contains capital letters. The call fails as an unknown tool.