MCP
MCP (Model Context Protocol) lets Agents connect to external tools and business services. You can find existing services in the Capability Center, connect a company or personal MCP, complete authentication, and then use it as your tasks require.
Entry: Capability Center > MCP.
This page is for members who need to use tools and for admins who connect and maintain MCP services. Search keywords: MCP, tool services, connection templates, OAuth, authentication, external clients.
Find and select an MCP service
Go to the MCP page, search by name, and filter services by source and category. You can also sort by Newest First, Most Calls, or Most Likes. Open the service details and review the introduction, tools, and configuration to confirm that it can complete your task.
- System MCP: Services preset by the platform. Their configuration is read-only and can't be edited or deleted here.
- Company MCP: Services visible within the same company, maintained by admins with company resource management permissions.
- Personal MCP: Services that you create and manage yourself, suitable for personal connection and verification.
To check tool names and purposes, view Tools in the details and expand the tool descriptions. The tool scope may change with the service configuration and authorization, so rely on the tool list currently returned.
If you want to use the built-in business capabilities of AE, read CLI first. Web conversations no longer offer System MCP as a selectable tool capability.
Connect a company or personal MCP
Before you start, prepare the connection URL, transport, and authentication information provided by the service provider. Go to the MCP page, click the create entry, and configure the service as follows.
- Select the scope. Regular members can create personal MCPs. Admins with company resource management permissions can create company MCPs. Company management permissions include Agent Admin and System Admin, and are not the same as admin permissions for a workspace.
- Select the connection method. If a matching template exists, you can use the Slack, Feishu OpenAPI, Lark OpenAPI, or DingTalk template and complete the form. For other services, select custom connection. Regular members can also use templates to create personal MCPs.
- Enter the connection information. Custom connections support SSE, HTTP, and Streamable HTTP, and the transport must match the service provider. Enter the name, service URL, and authentication information, and then save.
The Feishu OpenAPI and Lark OpenAPI templates use a platform-hosted connection method and require app information. This doesn't mean that you can run arbitrary local stdio commands in the general creation form.
To configure Header, OAuth, or app secret settings item by item, read MCP authentication and configuration guide.
Complete authentication and verify tools
A successful save doesn't mean that authentication is complete, or that every tool can be called. After the service is saved, complete the configuration for its authentication method, and then check the tool list and actual call results.
- No authentication: Use only when the service itself doesn't require credentials. You still need to check the URL and network connection.
- Manual header: Fill in the request headers as the service requires. Select encryption for sensitive values such as tokens and API keys, and don't put them in the name or description.
- OAuth 2.0: Follow the on-page guidance to complete authorization with the service provider. If the authorization page doesn't open automatically, use the Authenticate entry to continue. After you return, check the authentication status.
- App secret: Enter the app ID and app secret as the template requires, and complete the necessary app permission configuration with the service provider.
After configuration, open the service details to load the tool list, confirm the names and purposes, and then make a low-risk call with verifiable results in a conversation. A tool list that loads only means that the tool inventory was retrieved. Specific calls may still be limited by business data permissions or authorization scope.
To add authorization, select an authentication service, or handle authentication failures, read MCP authentication and configuration guide.
Use MCP in Agents and workspaces
After you connect an MCP, you still need to configure capabilities based on how you'll use it. Agent configuration, space-wide capabilities, and conversation selection serve different purposes. Creating an MCP doesn't automatically complete all of these settings.
- Let a specific Agent use tools: Associate available MCPs in that Agent's capability configuration. For details, see Agent.
- Configure common capabilities for a workspace: A space manager with the required permissions selects MCPs in the space capability settings. Shared spaces can't use personal MCPs. For the scope and steps, see Create a space.
- Use tools in a specific task: Go to the target space and conversation, check the current Agent, available capabilities, and authentication status, and then submit the task. For details, see Conversations.
What a company shares is the service configuration, not each person's OAuth authorization. Users still need to complete their own authentication and have the relevant business permissions. Joining a space doesn't automatically grant permission to manage company MCP configurations.
If you can't find System MCP in a conversation, use the business capability entry described in CLI. You don't need to keep trying to select or enable System MCP.
Connect external clients
Open the MCP details to view the current configuration. If the page provides an Add to client entry, follow the installation guide to select a client and complete the connection. If you configure it manually, first confirm that the client supports the corresponding transport and can access the service URL.
Not every MCP can be exported to your local machine. Regular remote services and platform-hosted connections have different requirements. When a company or personal MCP uses hosted OAuth, an app secret, or hosted stdio, it can't be exported directly as a regular remote configuration. The hosted configuration in the details also doesn't mean that it will run after you copy it to your local machine.
If the installation flow indicates that the configuration contains a static secret, first confirm that the target client is trusted, and then decide whether to export it. Don't paste tokens, secrets, or configurations that contain credentials into public documents, group chats, or code repositories.
Note that the mcp-token corresponds to the user's Agentic Engine identity, so all project permissions and roles still apply. Users can see only data in projects they already have access to, and data permissions still apply to query tools.
After connecting, check the tool list in the target client and verify the calls. If you run into authentication or configuration issues, see MCP authentication and configuration guide.
Maintenance, permissions, and FAQ
Enable or disable. The switch of a company MCP only changes the usage status for the current user and doesn't disable the service for the whole company. Personal MCPs are managed by their creators. System MCP doesn't provide this switch.
Edit Configuration. Personal MCPs are edited by their creators, and company MCPs are edited by admins with company resource management permissions. Changing the OAuth service URL or authentication configuration may invalidate existing authorizations, and changes to a company MCP may also require other users to authenticate again. Changing only display information doesn't clear authorizations.
Reauthenticate and disconnect authentication. When you're prompted that the service is not authenticated or needs reauthentication, follow the on-page guidance to complete authorization. Disconnect auth clears the current user's authorization for the service saved on the platform and disables the connection, but doesn't delete the company-shared MCP configuration. To use it again, you need to authenticate again.
Delete a service. You can delete only personal or company MCPs that you have management permissions for. System MCP can't be deleted. Deletion makes the service and related credentials unusable, so check whether any Agent, space, or conversation depends on it before you delete it.
- Can't find a service: Check the source and search conditions, and confirm whether it's a personal MCP that you created or an MCP of your company. Shared spaces can't use personal capabilities.
- Connection failed: Check the service URL, transport, network reachability, and Header configuration. Don't rely on Saved alone to judge whether the connection works.
- Tool list is empty or calls are rejected: Check the authentication status first, and then check the authorization scope, server-side tool configuration, and business data permissions. For temporary network or refresh failures, try again first. You don't always need to reauthorize.
- No edit entry: First check the resource source and your company resource management permissions. Being able to use a service doesn't mean that you can modify its configuration.
For detailed troubleshooting of authentication and configuration, see MCP authentication and configuration guide. If tools are available but still can't be used in tasks, see the capability selection instructions in Conversations.

