Skip to main content
An external client needs a personal MCP token and support for remote Streamable HTTP with a configured Bearer authorization header. First connect your tool accounts.

Create the connection

  1. Open Agent tools → Connect an agent.
  2. Create a token with a recognizable name, an expiry, and an optional project restriction.
  3. Copy the displayed token and client configuration into your client’s protected local settings.
  4. Refresh the client’s tool list. Use aixy_connections to inspect your connections.
  5. Ask the client to search for a permitted capability and review its proposed action.
Use the exact endpoint supplied by the dashboard; it follows your gateway deployment. The complete token and configuration are shown once. Keep them out of repositories, transcripts, and screenshots. The default token lifetime is 30 days. Choose 7, 30, 90, a custom 1–90 days, or Never according to your credential policy. A project restriction narrows access; it does not grant missing project membership or upstream permissions.

Connect a missing account

The agent can use aixy_connect to return the appropriate Aixy browser link. Open it and complete account authorization in the dashboard, then refresh the client’s tools. Provider tokens and OAuth codes belong in the connection flow, never in tool arguments or model messages. Use a model that supports function tools. The client must be able to call the search helper and then execute an action returned by discovery. Your client controls confirmations for external reads and writes; configure those approvals before using tools that change remote resources.

Disable or revoke a token

Disable blocks new MCP authentication and can be reversed before expiry. Revoke is permanent. These actions leave provider account connections in place and do not cancel external actions already sent. Expired or revoked credentials require a new token. Only the token owner manages their personal tokens. Suspension revokes the user’s tokens as part of removing access. Inspect MCP Activity when a call’s outcome is uncertain before attempting it again.