MCP servers
Attach remote HTTPS tool servers so an agent can call GitHub, Linear, Notion, Slack, or a server you run — without installing anything on our workers.
What this is
MCP (Model Context Protocol) is a standard for exposing tools over HTTP. setod acts as the client: you connect a remote server, we freeze its tool list, and those tools show up as pills on the agent like Gmail or Telegram.
We only speak Streamable HTTP. There is no stdio, no npx, and no process launched on our side. If a guide tells you to run a local MCP server on your laptop, that will not work here unless you expose it as a public HTTPS endpoint you control.
Catalog versus custom URL
- Catalog — GitHub, Linear, Notion, Slack, Atlassian, and Zapier. We fill in the official URL (Zapier asks you to paste the URL it generates).
- Custom MCP server — any HTTPS URL you run. We probe it first.
Both create the same connector type. Catalog cards are presets, not a different runtime.
How authentication is chosen
We do not ask you to pick OAuth versus a token up front. On connect we:
- Reject anything that is not HTTPS, and block private or reserved addresses
- Try
tools/listwith no credential - If the server returns 401 and advertises OAuth metadata, we start Sign in
- Otherwise we ask for a bearer token (a GitHub PAT, a Zapier key, and so on)
Slack needs its own OAuth app
Notion, Linear, and Atlassian register a client for us automatically. Slack does not. You create a Slack app, add our callback as a redirect URI, then paste the client ID and secret when you click Connect.
- Redirect URI is
PUBLIC_BASE_URLplus/connectors/oauth/mcp/callback. Locally that ishttp://localhost:8000/connectors/oauth/mcp/callbackwhen the env var is blank. - Slack: create an internal app at api.slack.com/apps. Unlisted apps cannot use Slack MCP. Turn on Agents & AI Apps → Model Context Protocol. Under OAuth & Permissions, add the redirect URI and the User Token Scopes Slack MCP lists (chat, channels, search, files, users, canvases).
- Optional: set
SLACK_MCP_CLIENT_IDandSLACK_MCP_CLIENT_SECRETon the API so Connect skips the paste step for everyone in this deployment.
Frozen tools
When the connector is saved, we store the tool names, descriptions, and schemas the server advertised. The agent uses that snapshot on every run. If the vendor adds or changes tools, use Re-sync on the connector card. We never refresh schemas silently — that is how a poisoned description would reach a scheduled agent.
Approvals
Write-like MCP tools (names containing create, update, delete, send, and similar) start as requires approval when you first attach the connector to an agent. Cycle the pill like any other tool: green (on), amber (approval), struck through (off).
What we will not do
- Run community MCP servers as subprocesses on the worker
- Expose setod itself as an MCP server (so Claude Desktop can call us)
- Load MCP resources, prompts, or sampling in this version
- Wake an agent from an MCP event — schedules and manual runs only