Connected services (MCP servers)
A connected service gives Operator's AI extra tools — Slack, Notion, Business Central, a system your team built, anything that speaks the Model Context Protocol. Once a service is switched on, its tools are available to the AI during your conversations.
Operator stores each service exactly as other MCP clients write it down, so a configuration you already have can be pasted in unchanged.
Three kinds of service
| Kind | Who can see it | Who adds it |
|---|---|---|
| My servers | Only you | Anyone, from the Capabilities page |
| Organizational | Everyone connected to that ERP.net instance | Power Users and Instance Admins |
| Agent's own | Whoever uses that agent | The agent's owner, in the agent editor |
Personal servers need no instance and no special role. Add one, switch it on, and the AI can use it in any of your conversations.
Adding a service
Open Capabilities → My servers → Add my own server. Two tabs describe the same thing:
- Settings — name, address, headers, sign-in and which tools the AI may use.
- Configuration — the raw JSON. Paste one in and the settings fill themselves; change a setting and the JSON follows.
A fixed-credential service looks like this:
{
"mcpServers": {
"businesscentral": {
"type": "http",
"url": "https://mcp.businesscentral.dynamics.com",
"headers": {
"TenantId": "${SECRET:BC_TENANT_ID}",
"EnvironmentName": "Production",
"Company": "CRONUS USA, Inc."
}
}
}
}
A service where each person signs in with their own account looks like this:
{
"mcpServers": {
"slack": {
"type": "http",
"url": "https://mcp.slack.com/mcp",
"oauth": {
"clientId": "YOUR_SLACK_APP_CLIENT_ID",
"scope": "channels:read chat:write"
}
}
}
}
Only services reachable over https are supported. A configuration that starts a program on your own machine cannot be used, and Operator says so instead of quietly ignoring it.
Placeholders in headers
Header values may contain placeholders, filled in only at the moment the service is called:
${SECRET:MY_TOKEN}— a value kept in Operator's secret store, never shown back to anyone.${ERPNET_INSTANCE_TOKEN}— the signed-in person's own ERP.net token, so the service acts as them.
If a placeholder has no value, that header is left out rather than sent half-empty.
Options Operator adds
Everything Operator needs beyond the standard lives under one x-operator key, so the rest of the entry stays a plain, portable configuration:
"x-operator": {
"displayName": "Slack",
"label": "slack",
"description": "Channels and messages",
"allowedTools": ["list_channels", "post_message"],
"requireApproval": "always"
}
callbackPort, which some desktop clients use, is accepted so a pasted configuration still works — Operator returns from sign-in through its own page instead.
Signing in
Services with a sign-in section authorize each person separately.
- Press Sign in on the service and approve it in the window that opens. Operator remembers the result and refreshes it silently while it stays valid.
- If an agent needs a service you have not signed in to, it says so in its answer and offers a Connect button right there. Approve it, then ask again.
- When a sign-in expires, the same button comes back. Disconnect forgets it entirely.
Some services hand out their own client id automatically; for those you can leave the client id empty.
Testing a service
Test connection performs a real handshake and lists the tools the service offers. Those tools then appear as checkboxes, so you can allow all of them or only the ones you want. Until a test has run, all tools are allowed.
If a connected MCP server fails while a conversation is starting, Operator names it in the error message when possible. Open Capabilities, test or disable that server, then try your message again.
Approval
By default the AI asks before each use of a connected service, the same way it asks before changing data. Turn Ask before each use off only for services you fully trust.
Examples
- "Post the weekly sales summary to the #sales channel." — uses your Slack service, after you have signed in.
- "Pull the open purchase orders from Business Central and compare them with ERP.net." — uses an organizational service with fixed credentials.
- "What can you do with my connected services?" — the agent lists the tools it currently has.