> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aixy-gateway.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect an agent

> Issue a personal MCP token and configure an external client.

An external client needs a personal MCP token and support for remote Streamable HTTP with a
configured Bearer authorization header. First [connect your tool accounts](/agent-tools/setup).

## Create the connection

1. Open **Agent tools → Connect an agent**.
2. Create a token with a recognizable name, an expiry, and an optional project restriction.
3. Copy the displayed token and client configuration into your client's protected local settings.
4. Refresh the client's tool list. Use `aixy_connections` to inspect your connections.
5. Ask the client to search for a permitted capability and review its proposed action.

Use the exact endpoint supplied by the dashboard; it follows your gateway deployment. The complete
token and configuration are shown once. Keep them out of repositories, transcripts, and screenshots.

The default token lifetime is 30 days. Choose 7, 30, 90, a custom 1–90 days, or **Never** according
to your credential policy. A project restriction narrows access; it does not grant missing project
membership or upstream permissions.

## Connect a missing account

The agent can use `aixy_connect` to return the appropriate Aixy browser link. Open it and complete
account authorization in the dashboard, then refresh the client's tools. Provider tokens and OAuth
codes belong in the connection flow, never in tool arguments or model messages.

Use a model that supports function tools. The client must be able to call the search helper and
then execute an action returned by discovery. Your client controls confirmations for external
reads and writes; configure those approvals before using tools that change remote resources.

## Disable or revoke a token

**Disable** blocks new MCP authentication and can be reversed before expiry. **Revoke** is
permanent. These actions leave provider account connections in place and do not cancel external
actions already sent. Expired or revoked credentials require a new token.

Only the token owner manages their personal tokens. Suspension revokes the user's tokens as part
of removing access. Inspect [MCP Activity](/agent-tools/overview#inspect-execution) when a call's
outcome is uncertain before attempting it again.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.