Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
54 changes: 47 additions & 7 deletions content/docs/configure-and-extend/connections-and-mcp.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -42,16 +42,56 @@ Local HTTP addresses also remain CLI-only. Web chat cannot reach your computer's

Disable or delete a saved server to exclude its tools from subsequent turns.
Servers stay private to the account that created them. In team scope, owners, admins, and developers can use their own saved servers. Viewers cannot use connection tools.
Saved `enabled_tools`, `disabled_tools`, and per-tool restrictions in **Extra JSON** also apply to chat.
Tools with an explicit `prompt` approval mode require Control, which can ask before a call.
Saved allowlists, blocklists, and per-tool restrictions also apply to chat.
Tools that need approval require Control, which can ask before a call.
Workspace chat, the Slack agent, and native-harness runs withhold these tools because they cannot ask.

The **Integrations** approval menu applies only to Integration entries. Saved servers use their own **Extra JSON** settings.
### Test a saved connection

Choose **Test connection** on a saved HTTP server. The test reads its saved URL and headers, then lists tools. It does not run tools.
The result shows the tool count, workspace chat availability, tools that require Control approval, and blocked tools.
Expand **Discovered tools** to inspect each tool's effective permission.

An error explains whether to check the public URL, authorization headers, missing secrets, invalid permission fields, or server response time.
A manual test allows six seconds for discovery. Closing the connection can add up to two seconds. A slow close does not turn a successful test into a failure.
This cleanup budget applies only to the manual test, not chat startup.
A successful connection with no tools shows a count of zero.
The test also checks disabled servers. Enable a server before its allowed tools become available.
Test local stdio servers through the CLI.

**Enabled** records a setting, not connection health. Results describe the last manual test during the current page visit.
They reset after saved settings change or the page reloads. Tests do not run automatically or monitor server health.
Chat still discovers tools at the start of each turn, so availability can change after a test.

### Set tool permissions

Choose **Edit** on an HTTP server and find **Tool permissions**.
The **Integrations** approval menu applies only to Integration entries.

| Setting | Effect |
| --- | --- |
| Default approval: Run automatically | Allows tools to run in workspace chat and Control without a separate approval. |
| Default approval: Ask in Control | Requires approval in Control. Other hosted chat surfaces withhold these tools. |
| Allow all tools unless blocked | Allows current and future tools, subject to block rules and approval. Turn this off to specify allowed names. |
| Allowed tools | Allows only the listed names. An empty list allows no tools. Enter one exact name per line. |
| Blocked tools | Excludes listed tools, even if an allowlist or approval rule permits them. |
| Per-tool approval | Overrides the default with Run automatically, Ask in Control, or Block. Use default removes the approval override. |

Test the saved connection before an edit to populate its tool names. **Add tool rule** also accepts an exact name without a test.
For a tool marked **Disabled in saved settings**, turn on the switch beside that label to enable it. Other block rules still apply.

Save changes to apply them on the next turn. The controls preserve unrelated CLI fields and permissions.
The form only saves valid permission values. If an earlier CLI or manual edit left an invalid policy, the structured controls cannot edit it.
Open **Extra JSON**, correct the invalid fields, then save. Mogplex withholds tools from invalid policies until you fix them.

Without an explicit approval mode, saved tools run automatically, like Integrations in web chat.
CLI approval defaults remain unchanged. Other CLI-specific extra options do not configure web chat.

For example, this **Extra JSON** allows `search` and `publish`, blocks `delete`, and asks before `publish` in Control.
The controls use the same fields as **Extra JSON**. Advanced edits remain available.
**Run automatically** maps to `auto`, **Ask in Control** to `prompt`, and per-tool **Block** to `deny`.
**Allowed tools** sets `enabled_tools`. **Blocked tools** sets `disabled_tools`.
The switch beside **Disabled in saved settings** sets `tools.<name>.enabled` to `true`.
For example, this JSON allows `search` and `publish`, blocks `delete`, and asks before `publish` in Control.
Replace these example names with the tool names your server exposes.

```json
Expand Down Expand Up @@ -195,7 +235,7 @@ A server that misses that deadline is left out. The deadline does not cancel lat

## Asking before a connection's tools run

This section describes **Integrations**. For saved MCP Servers, use the [Extra JSON permissions described above](#use-a-saved-server-in-web-chat).
This section describes **Integrations**. For saved MCP Servers, use [Tool permissions](#set-tool-permissions).

By default, tools from Integrations run without asking. You can
change that per connection: open the connection's menu in **Connections** (or the `auto` control on a row in the Connections pane) and choose
Expand Down Expand Up @@ -281,8 +321,8 @@ Use `/mcp` in the CLI to inspect MCP state during a session.
| Symptom | Check |
| --- | --- |
| Integration tool missing in a hosted run | Confirm the connection is enabled and included in the repo's resolved set. |
| Saved MCP tool missing in web chat | Confirm Enabled is on, the URL is public, and the server supports Streamable HTTP. Check saved tool restrictions and the startup deadline. |
| Saved MCP tool needs approval | Use Control for tools with an explicit `prompt` approval mode. Other hosted chat surfaces withhold them. |
| Saved MCP tool missing in web chat | Confirm the URL is public and the server supports Streamable HTTP. Choose Test connection, then check the result and each tool's permission. Enable the server to use its allowed tools. A server that misses the startup deadline stays out of that turn, even when an earlier test succeeded. |
| Saved MCP tool needs approval | Use Control for tools set to Ask in Control (`prompt` in Extra JSON). Other hosted chat surfaces withhold them. |
| Integration tool works globally but not in one repo | Check for a project exclusion or a project-specific connection cap. |
| CLI does not show cloud MCP servers | Confirm CLI token login, then inspect `/mcp` and the remote cache file. |
| OAuth preset stopped working | Reconnect it from Connections and retest before changing prompts. |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ description: Understand when a connection should be global, project-scoped, or e
Connections in Mogplex are not just account-wide settings.

This guide covers **Integrations**. The separate **MCP Servers** catalog applies across repos and does not use project exclusions.
See [saved servers in web chat](/configure-and-extend/connections-and-mcp#use-a-saved-server-in-web-chat) for that catalog's permissions and availability.
See how to [set tool permissions for saved servers](/configure-and-extend/connections-and-mcp#set-tool-permissions).

Integrations resolve at two levels:

Expand Down
2 changes: 2 additions & 0 deletions content/docs/web/settings.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -77,6 +77,8 @@ actually support them.

**Models** and **Connections** have their own sidebar destinations.
Open **Connections → MCP Servers** to manage saved servers for web chat and the CLI.
Use **Test connection** to check a saved HTTP server and list its tools without running them.
Edit [**Tool permissions**](/configure-and-extend/connections-and-mcp#set-tool-permissions) to set approval, allowlists, blocklists, and per-tool overrides. In hosted chat, tools that require approval run only in Control. The CLI uses its own prompts.
For model setup, see [Available Models](/web/models).

For the connection-specific operating guide, see
Expand Down
Loading