Skip to content

Connectors and MCP

An MCP connector lets Kiwi use approved tools exposed by another system. MCP stands for Model Context Protocol, an open standard for presenting tools and data sources to AI applications.

MCP connectors are implemented in Kiwi now. They must be enabled for the deployment, and management may be provided through an API or product integration rather than the Kiwi web interface. Contact the Kiwi team if you need to add one and do not see a supported management path.

When to use a connector

Use a connector when an agent needs a concrete action that is not in Kiwi's native tool catalogue, such as reading from an approved business service or starting a task in another system. Use a Skill instead when the missing piece is a repeatable method rather than system access.

From server to agent tool

  1. An owner registers the connector's secure server address and authentication mode.
  2. Kiwi discovers the tools advertised by that MCP server.
  3. The owner or administrator reviews, names, and enables only the tools that should be available. Discovery alone does not approve a tool.
  4. An enabled connector tool is assigned explicitly to an agent.
  5. During a conversation, the agent may call it with the arguments needed for the task. Kiwi checks the requester's access again before the call.

Connector tools are not automatically included when an agent receives all native tools. This keeps new or changed external capabilities from appearing on agents without an explicit decision.

Ownership, identity, and administration

  • A private connector is visible to its members and managed by its owners. An administrator does not automatically bypass that private membership.
  • A public connector is visible more broadly. Creating or changing public connectors and their tool policies requires an administrator.
  • A connector can require each user to connect their own account, use no credentials, or use an administrator-managed shared credential. Shared credentials are reserved for trusted use cases and require an administrator.
  • Stored connector credentials are encrypted and are not returned in plain text.

Check before enabling a tool

An MCP server is an external trust boundary. Before enabling one, confirm:

  • who operates the server and what its tools do;
  • what prompts, file content, identifiers, or other arguments may be sent;
  • which users should see the connector and which agents need each tool;
  • whether the tool reads data, changes data, or triggers an external action;
  • what the external service does with requests, credentials, and results.

Turning off web search does not disable connector calls. Remove or withhold the MCP tool from an agent when that agent should not reach the connected system. See Security and data handling for the wider data-flow picture.

Product-module rollout

General MCP connector support is available today. Dedicated MCP servers for each MRCL Make module and MRCL Ideate are a separate, future rollout. See Coming soon for that planned module integration.


Related: Skills · Tools · Security and data handling · FAQ