MCP servers

Attach remote HTTPS tool servers so an agent can call GitHub, Linear, Notion, Slack, or a server you run — without installing anything on our workers.

What this is

MCP (Model Context Protocol) is a standard for exposing tools over HTTP. setod acts as the client: you connect a remote server, we freeze its tool list, and those tools show up as pills on the agent like Gmail or Telegram.

We only speak Streamable HTTP. There is no stdio, no npx, and no process launched on our side. If a guide tells you to run a local MCP server on your laptop, that will not work here unless you expose it as a public HTTPS endpoint you control.

Catalog versus custom URL

  • Catalog — GitHub, Linear, Notion, Slack, Atlassian, and Zapier. We fill in the official URL (Zapier asks you to paste the URL it generates).
  • Custom MCP server — any HTTPS URL you run. We probe it first.

Both create the same connector type. Catalog cards are presets, not a different runtime.

How authentication is chosen

We do not ask you to pick OAuth versus a token up front. On connect we:

  • Reject anything that is not HTTPS, and block private or reserved addresses
  • Try tools/list with no credential
  • If the server returns 401 and advertises OAuth metadata, we start Sign in
  • Otherwise we ask for a bearer token (a GitHub PAT, a Zapier key, and so on)
Official Notion, Slack, and Atlassian remotes typically require OAuth. GitHub and Zapier usually accept a pasted token. Linear supports both.

Slack needs its own OAuth app

Notion, Linear, and Atlassian register a client for us automatically. Slack does not. You create a Slack app, add our callback as a redirect URI, then paste the client ID and secret when you click Connect.

  • Redirect URI is PUBLIC_BASE_URL plus /connectors/oauth/mcp/callback. Locally that is http://localhost:8000/connectors/oauth/mcp/callback when the env var is blank.
  • Slack: create an internal app at api.slack.com/apps. Unlisted apps cannot use Slack MCP. Turn on Agents & AI Apps → Model Context Protocol. Under OAuth & Permissions, add the redirect URI and the User Token Scopes Slack MCP lists (chat, channels, search, files, users, canvases).
  • Optional: set SLACK_MCP_CLIENT_ID and SLACK_MCP_CLIENT_SECRET on the API so Connect skips the paste step for everyone in this deployment.

Frozen tools

When the connector is saved, we store the tool names, descriptions, and schemas the server advertised. The agent uses that snapshot on every run. If the vendor adds or changes tools, use Re-sync on the connector card. We never refresh schemas silently — that is how a poisoned description would reach a scheduled agent.

Approvals

Write-like MCP tools (names containing create, update, delete, send, and similar) start as requires approval when you first attach the connector to an agent. Cycle the pill like any other tool: green (on), amber (approval), struck through (off).

What we will not do

  • Run community MCP servers as subprocesses on the worker
  • Expose setod itself as an MCP server (so Claude Desktop can call us)
  • Load MCP resources, prompts, or sampling in this version
  • Wake an agent from an MCP event — schedules and manual runs only
NextWriting instructions →