Skip to content
Myra AI Workspace Tenant Manual Updated · 01 Sep 2026

Managing the MCP connectors of the tenant

A connector for the Model Context Protocol (MCP) makes the tools of an external server available to the AI in the chat.

Creating an MCP connector

The following requirements are met:

  • ☑ Your user account has the Manage tenant settings permission.
  • ☑ The address of the MCP server and the related credentials are available.

Proceed as follows to create an MCP connector:

MCP Connectors view with the New connector button

MCP Connectors view

  • ► In the Settings area, open the Connections group and its MCP Connectors tab.

    • ▷ On the start page, click on your name at the bottom of the navigation bar.
    • ↳ The user menu opens.

    User menu with the groups and the Log out entry

    User menu

    • ▷ In the My Account group, click on the Settings entry.
    • ↳ The navigation bar shows the Settings area.

    Navigation bar in the Settings area

    Navigation bar in the Settings area

    • ▷ In the navigation bar, click on the Connections group.
    • ▷ Open the MCP Connectors tab.
    • ► Click on the New connector button.
    • ↳ The New MCP Connector dialog opens.

New MCP Connector dialog with the Credential scope selection

New MCP Connector dialog

  • ► Enter the name.
  • ► Under Credential scope, select whether the connector is Tenant-shared or Per-user.
  • ► Enter the address of the server.
  • ► Give the credentials.
  • ► Save the connector.
  • ➔ Myra AI Workspace creates the connector. The AI calls its tools in the chat.

MCP connectors view with the new connector in the list

MCP connectors view with the new connector

Note

The test of a connector needs a saved connector. Before that, the dialog shows Save the connector first, then test.

Entries in the New MCP Connector dialog

New MCP Connector dialog with the Credential scope selection

New MCP Connector dialog

You set the following entries when you create the connector:

Entry Description
Name Name of the connector in the list, for example My Tools Server. The entry is mandatory.
Credential scope Tenant-shared stores a single auth value on the connector that every user of the tenant uses. That is the right scope for an internal MCP server without a sign-in per person. Per-user asks every person for their own credential. That is the right scope for a service such as Gmail or GitHub whose token represents a specific person. The users then connect themselves in the My MCP Connectors view.
Microsoft Entra tenant ID Directory identifier of your organization as a GUID from the Entra admin center. The entry appears for a tenant-scoped Microsoft 365 connector only, and when you create it only. Myra AI Workspace derives the server URL and the sign-in addresses from it. The Server URL is then read-only. The entry is mandatory.
Server URL JSON-RPC 2.0 endpoint of the MCP server, for example https://my-mcp-server.example.com/mcp. The entry is mandatory.
Authentication Method with which the connector signs in to the server. For Tenant-shared, None, Bearer token, and Custom header are available. For Per-user, None and Bearer token are available. For Bearer token, you enter the token, for Custom header, the header in the Header-Name: header-value format, for example X-Api-Key: your-secret-value.
Tool permissions Basic rule for the tools of this connector: Allow by default or Block by default. Myra AI Workspace enforces the rule on the server. A blocked tool never runs.

If you select Per-user and Bearer token, the OAuth (advanced) area gives you these entries in addition:

Entry Description
Authorize URL Address at which the users sign in to the provider.
Token URL Address at which the provider issues the tokens.
OAuth Client ID Identifier of the OAuth app at the provider. For a Microsoft 365 connector, the entry is mandatory.
OAuth Client Secret Secret of the OAuth app. Myra AI Workspace stores it encrypted and never shows it again. PKCE is always used. For a public client, the field stays blank.
Scopes Space-separated permissions that the sign-in requests. For Microsoft Entra, they include offline_access and the resource scope so that access is refreshed without a new sign-in.

The following options are available in the dialog:

Option Description
Test connection button Calls the server and shows Connected ✓ or Connected ✓ — tool(s) found. The button appears for Tenant-shared only, because only there the credential is in the dialog. The button is disabled while the Server URL is empty.
Create button Creates the connector. While it stores, the button carries the Saving… label.
Cancel button Closes the dialog without creating the connector.

Note

If a mandatory entry is missing, the dialog shows Name is required, Server URL is required, Microsoft Entra tenant ID is required. or OAuth client ID is required for a Microsoft 365 connector.

Note

On a test, the dialog shows Save the connector first, then test. while the connector is not stored yet, Connect required — add your credential first. while no credential is available, and Error: on an error.

Editing an MCP connector

Proceed as follows to edit an MCP connector:

MCP Connectors view with the list of the connectors

MCP Connectors view

  • ► In the Settings area, open the Connections group and its MCP Connectors tab.

    • ▷ On the start page, click on your name at the bottom of the navigation bar.
    • ↳ The user menu opens.

    User menu with the groups and the Log out entry

    User menu

    • ▷ In the My Account group, click on the Settings entry.
    • ↳ The navigation bar shows the Settings area.

    Navigation bar in the Settings area

    Navigation bar in the Settings area

    • ▷ In the navigation bar, click on the Connections group.
    • ▷ Open the MCP Connectors tab.
    • ► Open the connector.
    • ↳ The Edit MCP Connector dialog opens.

Edit MCP Connector dialog with the connector ID

Edit MCP Connector dialog

  • ► Change the data.
  • ► Save the connector.
  • ➔ Myra AI Workspace applies the change.

MCP connectors view with the connector changed

MCP connectors view

Note

The field for the stored secret stays empty. Leave it empty to keep the stored secret.

Entries in the Edit MCP Connector dialog

Edit MCP Connector dialog with the connector ID

Edit MCP Connector dialog

You change the following entries in the dialog:

Entry Effect of the change
Name Changes the name in the list and in the selection of the tools in the chat.
Credential scope Switches between a shared and a personal access. After a change to Per-user, every person connects themselves in the My MCP Connectors view. Until then, the AI does not call the tools for that person. After a change to Tenant-shared, the value stored on the connector applies to every user of the tenant.
Server URL Points the connector at a different server. The AI then calls the tools of this server. If the credential is not valid there, the calls fail. For a Microsoft 365 connector, the entry is read-only.
Authentication Changes the sign-in method. On a change, Myra AI Workspace discards the value entered so far. Store the credential again afterwards.
OAuth Client Secret Replaces the stored secret. If you leave the field blank, Myra AI Workspace keeps the stored secret.
Tool permissions Changes which tools the AI calls. The change applies immediately to each new call and to every user of the tenant. A blocked tool never runs.

The following entry is no longer changeable after the connector is created:

Entry Description
Connector ID Identifier of the connector. You address the connector by this identifier from the API. The Copy button puts the identifier on the clipboard.

Note

The per-tool exceptions are available in the Edit MCP Connector dialog only, because they need a stored connector. While the tools are not loaded, the Tool permissions area carries the note that you load this connector's tools with the Test connection button and then set per-tool exceptions. For each tool, you then set Allow or Block.

Deleting an MCP connector

Proceed as follows to delete an MCP connector:

MCP Connectors view with the list of the connectors

MCP Connectors view

  • ► In the Settings area, open the Connections group and its MCP Connectors tab.

    • ▷ On the start page, click on your name at the bottom of the navigation bar.
    • ↳ The user menu opens.

    User menu with the groups and the Log out entry

    User menu

    • ▷ In the My Account group, click on the Settings entry.
    • ↳ The navigation bar shows the Settings area.

    Navigation bar in the Settings area

    Navigation bar in the Settings area

    • ▷ In the navigation bar, click on the Connections group.
    • ▷ Open the MCP Connectors tab.
    • ► Delete the connector.
    • ↳ The Delete this MCP connector? The model will no longer have access to its tools. query opens.

Query before the deletion of an MCP connector

Delete MCP connector query

  • ► Confirm the query.
  • ➔ Myra AI Workspace deletes the connector.

MCP connectors view without the connector deleted

MCP connectors view without the connector

Effects of the deletion

The deletion has the following effects:

Object Effect
Connector Myra AI Workspace removes the connector from the list. The connector cannot be restored.
Credentials Myra AI Workspace deletes the credential stored on the connector and, for a connector with the Per-user scope, the tokens of every user as well. The tokens at the provider stay. Revoke them there if they are no longer to be valid.
Tool permissions The basic rule and the per-tool exceptions go with the connector.
Chat The AI no longer calls the tools of this server for any person of the tenant. A task that needs such a tool then fails.
Agents An agent that uses this tool continues to work without the tool. Check the agents concerned before the deletion.
API Calls that address the connector by its Connector ID no longer find it.

Note

These tasks need the Manage tenant settings permission. The AI Manager and Finance roles do not have it. The AI Manager role manages its own connectors instead.