Managing MCP connectors¶
A connector for the Model Context Protocol (MCP) makes the tools of an external server available to the AI in the chat.
Creating an MCP connector¶
The following requirements are met:
- ☑ Your user account has the Manage tenant settings permission.
- ☑ The address of the MCP server and the related credentials are available.
Proceed as follows to create an MCP connector:
MCP Connectors view
-
► In the Settings area, open the Connections group and its MCP Connectors tab.
- ▷ On the start page, click on your name at the bottom of the navigation bar.
- ↳ The user menu opens.
User menu
- ▷ In the My Account group, click on the Settings entry.
- ↳ The navigation bar shows the Settings area.
Navigation bar in the Settings area
- ▷ In the navigation bar, click on the Connections group.
- ▷ Open the MCP Connectors tab.
- ► Click on the New connector button.
- ↳ The New MCP Connector dialog opens.
New MCP Connector dialog
- ► Enter the name.
- ► Under Credential scope, select whether the connector is Tenant-shared or Per-user.
- ► Enter the address of the server.
- ► Give the credentials.
- ► Save the connector.
- ➔ Myra AI Workspace creates the connector. The AI calls its tools in the chat.
MCP connectors view with the new connector
Note
The test of a connector needs a saved connector. Before that, the dialog shows Save the connector first, then test.
Entries in the New MCP Connector dialog¶
New MCP Connector dialog
You set the following entries when you create the connector:
| Entry | Description |
|---|---|
| Name | Name of the connector in the list, for example My Tools Server. The entry is mandatory. |
| Credential scope | Tenant-shared stores a single auth value on the connector that every user of the tenant uses. That is the right scope for an internal MCP server without a sign-in per person. Per-user asks every person for their own credential. That is the right scope for a service such as Gmail or GitHub whose token represents a specific person. The users then connect themselves in the My MCP Connectors view. |
| Microsoft Entra tenant ID | Directory identifier of your organization as a GUID from the Entra admin center. The entry appears for a tenant-scoped Microsoft 365 connector only, and when you create it only. Myra AI Workspace derives the server URL and the sign-in addresses from it. The Server URL is then read-only. The entry is mandatory. |
| Server URL | JSON-RPC 2.0 endpoint of the MCP server, for example https://my-mcp-server.example.com/mcp. The entry is mandatory. |
| Authentication | Method with which the connector signs in to the server. For Tenant-shared, None, Bearer token, and Custom header are available. For Per-user, None and Bearer token are available. For Bearer token, you enter the token, for Custom header, the header in the Header-Name: header-value format, for example X-Api-Key: your-secret-value. |
| Tool permissions | Basic rule for the tools of this connector: Allow by default or Block by default. Myra AI Workspace enforces the rule on the server. A blocked tool never runs. |
If you select Per-user and Bearer token, the OAuth (advanced) area gives you these entries in addition:
| Entry | Description |
|---|---|
| Authorize URL | Address at which the users sign in to the provider. |
| Token URL | Address at which the provider issues the tokens. |
| OAuth Client ID | Identifier of the OAuth app at the provider. For a Microsoft 365 connector, the entry is mandatory. |
| OAuth Client Secret | Secret of the OAuth app. Myra AI Workspace stores it encrypted and never shows it again. PKCE is always used. For a public client, the field stays blank. |
| Scopes | Space-separated permissions that the sign-in requests. For Microsoft Entra, they include offline_access and the resource scope so that access is refreshed without a new sign-in. |
The following options are available in the dialog:
| Option | Description |
|---|---|
| Test connection button | Calls the server and shows Connected ✓ or Connected ✓ — |
| Create button | Creates the connector. While it stores, the button carries the Saving… label. |
| Cancel button | Closes the dialog without creating the connector. |
Note
If a mandatory entry is missing, the dialog shows Name is required, Server URL is required, Microsoft Entra tenant ID is required. or OAuth client ID is required for a Microsoft 365 connector.
Note
On a test, the dialog shows Save the connector first, then test. while the connector is not stored yet, Connect required — add your credential first. while no credential is available, and Error:
Editing an MCP connector¶
Proceed as follows to edit an MCP connector:
MCP Connectors view
-
► In the Settings area, open the Connections group and its MCP Connectors tab.
- ▷ On the start page, click on your name at the bottom of the navigation bar.
- ↳ The user menu opens.
User menu
- ▷ In the My Account group, click on the Settings entry.
- ↳ The navigation bar shows the Settings area.
Navigation bar in the Settings area
- ▷ In the navigation bar, click on the Connections group.
- ▷ Open the MCP Connectors tab.
- ► Open the connector.
- ↳ The Edit MCP Connector dialog opens.
Edit MCP Connector dialog
- ► Change the data.
- ► Save the connector.
- ➔ Myra AI Workspace applies the change.
MCP connectors view
Note
The field for the stored secret stays empty. Leave it empty to keep the stored secret.
Entries in the Edit MCP Connector dialog¶
Edit MCP Connector dialog
You change the following entries in the dialog:
| Entry | Effect of the change |
|---|---|
| Name | Changes the name in the list and in the selection of the tools in the chat. |
| Credential scope | Switches between a shared and a personal access. After a change to Per-user, every person connects themselves in the My MCP Connectors view. Until then, the AI does not call the tools for that person. After a change to Tenant-shared, the value stored on the connector applies to every user of the tenant. |
| Server URL | Points the connector at a different server. The AI then calls the tools of this server. If the credential is not valid there, the calls fail. For a Microsoft 365 connector, the entry is read-only. |
| Authentication | Changes the sign-in method. On a change, Myra AI Workspace discards the value entered so far. Store the credential again afterwards. |
| OAuth Client Secret | Replaces the stored secret. If you leave the field blank, Myra AI Workspace keeps the stored secret. |
| Tool permissions | Changes which tools the AI calls. The change applies immediately to each new call and to every user of the tenant. A blocked tool never runs. |
The following entry is no longer changeable after the connector is created:
| Entry | Description |
|---|---|
| Connector ID | Identifier of the connector. You address the connector by this identifier from the API. The Copy button puts the identifier on the clipboard. |
Note
The per-tool exceptions are available in the Edit MCP Connector dialog only, because they need a stored connector. While the tools are not loaded, the Tool permissions area carries the note that you load this connector's tools with the Test connection button and then set per-tool exceptions. For each tool, you then set Allow or Block.
Deleting an MCP connector¶
Proceed as follows to delete an MCP connector:
MCP Connectors view
-
► In the Settings area, open the Connections group and its MCP Connectors tab.
- ▷ On the start page, click on your name at the bottom of the navigation bar.
- ↳ The user menu opens.
User menu
- ▷ In the My Account group, click on the Settings entry.
- ↳ The navigation bar shows the Settings area.
Navigation bar in the Settings area
- ▷ In the navigation bar, click on the Connections group.
- ▷ Open the MCP Connectors tab.
- ► Delete the connector.
- ↳ The Delete this MCP connector? The model will no longer have access to its tools. query opens.
Delete MCP connector query
- ► Confirm the query.
- ➔ Myra AI Workspace deletes the connector.
MCP connectors view without the connector
Effects of the deletion¶
The deletion has the following effects:
| Object | Effect |
|---|---|
| Connector | Myra AI Workspace removes the connector from the list. The connector cannot be restored. |
| Credentials | Myra AI Workspace deletes the credential stored on the connector and, for a connector with the Per-user scope, the tokens of every user as well. The tokens at the provider stay. Revoke them there if they are no longer to be valid. |
| Tool permissions | The basic rule and the per-tool exceptions go with the connector. |
| Chat | The AI no longer calls the tools of this server for any person of the tenant. A task that needs such a tool then fails. |
| Agents | An agent that uses this tool continues to work without the tool. Check the agents concerned before the deletion. |
| API | Calls that address the connector by its Connector ID no longer find it. |







