> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aixy-gateway.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure tools and accounts

> Enable an MCP connection, select allowed actions, and connect user accounts.

An organization administrator configures a tool connection. Members then authorize their own
accounts and receive only the actions allowed by both Aixy and the upstream service.

## Enable a connection

1. Open **Agent tools → Enable tools**.
2. Choose a provider and select **Enable tool**, or choose **Add custom tool**.
3. Choose organization-wide or project access and configure authentication.
4. Save the connection. When the editor needs a saved configuration before discovery, use
   **Save and continue**.
5. Connect your account, discover the catalog, select permitted tools, and save the selection.

The connection can exist with no allowed tools. Account authorization alone does not grant action
permissions. Search and catalog filters do not select actions automatically. **Allow all current
and future tools** also grants access to actions the upstream adds later, so choose it deliberately.

## Choose how accounts connect

With **OAuth managed by Aixy**, members select **Connect account** and complete the provider's
consent screen. Administrators configure access and tools; each member supplies their own consent.
Provider organization policies and app approvals still apply.

For customer-owned authentication, use the method shown by the selected preset: personal bearer
credentials, an authorization header, or a registered OAuth application. For OAuth, register the
exact callback shown in the editor and enter the application details there. Save client secrets
only in the credential fields.

| Provider | Account setup |
| - | - |
| GitHub | Connect with the configured OAuth application or an individual PAT; the user's GitHub permissions still apply. |
| Slack | Authorize the configured Slack application for the workspace the user intends to use. |
| Atlassian Jira | Use the configured OAuth flow or the email and scoped API-token flow shown in the editor. Select actions from the returned catalog. |
| Notion | Authorize the hosted MCP connection through OAuth for the intended workspace. |

Successful discovery checks current upstream access. A saved account alone means that a
credential is present. Personal credentials are isolated by organization, connection, and user;
members do not inherit an administrator's account.

## Add a custom MCP server

Use a public HTTPS server implementing **Streamable HTTP**. Configure its URL and supported
authentication in **Add custom tool**. For a registered OAuth application, use authorization code
with PKCE S256 and the callback shown by Aixy. Refresh tokens are used when supplied by the provider.

Aixy exposes the server's tools. Select servers whose tools work without server-initiated sampling,
elicitation, or additional resource workflows. Validate discovery and a permitted action before
sharing the connection with the organization.

## Maintain connections

Members use **Manage** on their account connection to reconnect or disconnect. Administrators
can turn off **Enabled for the organization** to pause access while retaining the configuration,
or remove a connection and its saved accounts.

Changing the server URL or authentication clears existing account connections and requires new
consent. For an existing shared connection, **Switch to personal accounts** is an explicit change
that clears its saved connections. Check the selected scope and tool list before saving.

A tool provider receives action arguments, and the client may send tool results to its model.
Choose accounts, actions, and model destinations appropriate for the data involved. Continue to
[Connect an agent](/agent-tools/connect-agent) or [Playground tools](/agent-tools/playground).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.