
The MCP Servers panel before anything is connected.
Adding a Server

The Add MCP Server form.
URLs Are Checked Before They Are Accepted
The URL is validated against a set of rules that block servers on private or internal addresses. The hostname is resolved first, so a public name pointing at an internal address is rejected too.Connection States
Shared or Individual Credentials
Shared means one credential set is used by everyone on the project. Individual means the server definition is visible to everyone, but each person authorises with their own credentials. Shared is the default. Choose Individual when the external service should see who is acting rather than one shared identity.How the Agent Uses Them
Tools from your connected servers are added to the agent’s own set for that project. They are treated cautiously by default: the platform does not assume an external tool is read-only, and none of them are available in Ask mode. That last point is deliberate. Ask mode is a read-only boundary, and an external tool could write, so MCP tools are excluded from it entirely.Your Next Step
Connected tools widen what a build can do. What the agent does with them follows the same rules as everything else.See the agent's own capabilities
The nineteen built-in capabilities and the boundaries around them.
Provide a service key instead
How third-party credentials are requested and stored.