Servers

A named handful of tools at its own address. Give one to an agent instead of your whole account. Servers shared with you appear here too.

How agents choose a server

Three ways, from most to least durable. Whichever way, an agent is only offered tools its person already reaches.

1. Connect to a server's own address

Every server has an address on its Connect button. A session opened there is that server and cannot switch away; its sign-in and keys work nowhere else. Use this when mixing servers up would matter — one connector per server, nothing to remember afterwards.

2. Tell the agent which server to work on

In any session — desktop apps included — say work on Acme, or give the folder's path. Say work on everything to go back. work_on with no arguments reports the current choice and changes nothing.

A server decides this for itself, under its Settings.

3. Bind a folder command line only

Add the address below once to Claude Code or Cursor in the terminal. A session started in a bound folder is served that folder's server. Desktop app connectors cannot report a folder, so there the session gets everything, as if nothing were bound — use work on instead. A server's own address is never re-routed.

New server

Tools that do more are greyed out below, and refused if an agent calls one anyway — from a script too. A tool Inline cannot classify counts as deleting, so only Everything includes it.
Only tools you can reach are listed — MCP tools and REST API endpoints alike — and they are checked again when you save.

Settings

These belong to the server, so they are the same for everyone who uses it.

How agents find tools
Practice mode
Everything else still applies exactly as it would for a real call: this server's tool list, the key's scope, what agents may do, your rules, approvals that hold a call for a person, and the audit trail. A call that would be refused is still refused — that is the point of rehearsing. Made-up results are shaped by each operation's own response schema, with values that could not be mistaken for real data, and the same call rehearsed twice gives the same answer.
Scripts
Leave empty for the defaults. A run gets 60 seconds unless the script asks for more, up to this server's cap: 1–180 seconds (default cap 120). Tool calls per run: 1–500 (default 100). They apply to scripts and registered tools on this server only.
Call limits …
Rules and approvals …

Force or require arguments, block a tool, hold calls for a person's approval, ask a webhook, or filter responses — for every call on this server.

Playbooks

The steps that worked for a task on this server, taken from scripts that succeeded here at least twice. Approved playbooks are shown to agents searching this server — never on any other. Edit a suggestion before approving it; a rejected one is not suggested again.

Loading playbooks…

Connect

Add the address as a connector and leave authentication set to required. You approve it in the browser, and the tools you get are this server's list. Nothing to paste, nothing to keep secret. The activity log records you.
The key reaches this server and nothing else, and the log records it alongside you. It has no list of its own — edit the server and its keys follow. New value replaces one in place, keeping its name, this server and its remaining lifetime.
The same tools and the same limits, with a key as the bearer — for a shell script or a language with no MCP client.

Bind a folder

Sessions started here — or anywhere beneath it — use the server below. The most specific binding wins, so a subfolder can point somewhere else.
Only servers you own. Binding steers between what you already hold; it never adds anything.

Your key

The shape most MCP clients take for a remote server. Its tool list will be exactly this server's — which is how you check it is scoped the way you meant.