Connected services (MCP servers)

A connected service gives Operator's AI extra tools — Slack, Notion, Business Central, a system your team built, anything that speaks the Model Context Protocol. Once a service is switched on, its tools are available to the AI during your conversations.

Operator stores each service exactly as other MCP clients write it down, so a configuration you already have can be pasted in unchanged.

Three kinds of service

Kind Who can see it Who adds it
My servers Only you Anyone, from the Capabilities page
Organizational Everyone connected to that ERP.net instance Power Users and Instance Admins
Agent's own Whoever uses that agent The agent's owner, in the agent editor

Personal servers need no instance and no special role. Add one, switch it on, and the AI can use it in any of your conversations.

Adding a service

Open Capabilities → My servers → Add my own server. Two tabs describe the same thing:

A fixed-credential service looks like this:

{
  "mcpServers": {
    "businesscentral": {
      "type": "http",
      "url": "https://mcp.businesscentral.dynamics.com",
      "headers": {
        "TenantId": "${SECRET:BC_TENANT_ID}",
        "EnvironmentName": "Production",
        "Company": "CRONUS USA, Inc."
      }
    }
  }
}

A service where each person signs in with their own account looks like this:

{
  "mcpServers": {
    "slack": {
      "type": "http",
      "url": "https://mcp.slack.com/mcp",
      "oauth": {
        "clientId": "YOUR_SLACK_APP_CLIENT_ID",
        "scope": "channels:read chat:write"
      }
    }
  }
}

Only services reachable over https are supported. A configuration that starts a program on your own machine cannot be used, and Operator says so instead of quietly ignoring it.

Placeholders in headers

Header values may contain placeholders, filled in only at the moment the service is called:

If a placeholder has no value, that header is left out rather than sent half-empty.

Options Operator adds

Everything Operator needs beyond the standard lives under one x-operator key, so the rest of the entry stays a plain, portable configuration:

"x-operator": {
  "displayName": "Slack",
  "label": "slack",
  "description": "Channels and messages",
  "allowedTools": ["list_channels", "post_message"],
  "requireApproval": "always"
}

callbackPort, which some desktop clients use, is accepted so a pasted configuration still works — Operator returns from sign-in through its own page instead.

Signing in

Services with a sign-in section authorize each person separately.

Some services hand out their own client id automatically; for those you can leave the client id empty.

Testing a service

Test connection performs a real handshake and lists the tools the service offers. Those tools then appear as checkboxes, so you can allow all of them or only the ones you want. Until a test has run, all tools are allowed.

If a connected MCP server fails while a conversation is starting, Operator names it in the error message when possible. Open Capabilities, test or disable that server, then try your message again.

Approval

By default the AI asks before each use of a connected service, the same way it asks before changing data. Turn Ask before each use off only for services you fully trust.

Examples