External MCP connections let RunReveal agents use tools hosted by another service. This is separate from connecting an external assistant to RunReveal's MCP server. Availability depends on your workspace's MCP feature access.
Add a server
Workspace administrators can open Settings → Integrations → Add MCP server to approve a server
for the workspace. Other workspace members with mcp_servers#read can view approved servers and
sign in to them with their own account, but cannot add, edit, enable, disable, or delete servers.
- Enter a workspace-unique Server name, an optional display label, and the server's HTTPS endpoint. The name becomes part of exposed tool names and cannot be changed after creation.
- Leave Requires OAuth authorization on unless the server intentionally requires no authentication. Do not enter API keys, tokens, secrets, or credentials in the endpoint.
- Choose Verify and save. RunReveal checks that the endpoint answers before saving it. A server advertising zero tools is still valid.
Adding a server does not sign anybody in to it, including the administrator who added it. Sessions are per user: each member, administrators included, chooses Connect on the server and completes the vendor's consent for their own account. Your session is used by your own chats and by agents you created (see Grant access to an agent).
A server that cannot be verified is not saved. OAuth deployment-configuration errors require assistance from your RunReveal deployment administrator, not another attempt.
Manage a connection
- Test connection uses your connection to perform fresh discovery for just that server and reports tool count or a specific authorization, scope, connectivity, or protocol failure. Results are temporary, not continuous health monitoring. Disabled servers can be tested without enabling them.
- Edit changes the label, endpoint, authentication mode, or enabled state. Connection changes are verified before replacing the existing settings. Changing the endpoint or authentication mode disconnects every user's session. Failed edits leave the old settings intact. Successful edits retain the config ID and existing agent grants. Only workspace administrators can edit a server.
- Enable requires fresh verification. Failure leaves the server disabled.
- Connect signs you in to the server with your own account. It affects nobody else's session.
- Reconnect re-authenticates your own account and is deliberately different from editing: starting it immediately clears your existing credentials. Agent grants are retained, but you cannot use the server until consent and verification succeed. Failed or abandoned reconnection leaves you unconnected. No-auth servers have no consent action.
- Delete previews affected agents, then permanently removes the approved server, every member's session, and all agent references, including any grants added after the preview. Only workspace administrators can delete a server.
If workspace MCP access is disabled, existing connections can still be inspected and deleted. They cannot be created, changed, authenticated, tested, or used.
Grant access to an agent
In the agent form, use External MCP servers, separately from the internal Available Tools list. Select server configurations by their displayed labels; grants are bound to config IDs, not names.
A grant gives the agent access to every tool advertised by that external server. It does not add
RunReveal role permissions. No selection means no external MCP access.
Editing grants requires agents#edit, and viewing the picker requires mcp_servers#read; workspace
administrator access is not required to sign in to a server and use your own session.
Agent runs, whether scheduled or started with Run now, use the connection of the user who created the agent, not the user who triggers or edits it. Anyone who can edit or run the agent can therefore use the creator's vendor access through it. If the creator has not connected the server, or disconnects later, the run reports the server as unavailable and continues without its tools.
New grants require an enabled no-auth server, or an enabled server you have connected. This check uses your connection even when you edit an agent someone else created. Existing grants can be retained or removed when a server becomes disabled or loses authorization, but retention does not make the server usable. Remove unresolved references before saving. If the server list cannot be loaded or you lack read permission, unrelated agent edits preserve existing grants.
Use servers in chat
Chat offers the tools of every enabled server that needs no authentication or that you have connected, using your own connection. Servers you have not connected are left out.