Connect and control MCP servers
Review the built-in ERP tools, add an outside server with the wizard, control each tool's risk and approval, and test tools safely.
Required permission: ai.configure
Before you begin
- MCP servers must be on in Applications > AI Assistant > Features and MCP must be on in Settings > General.
- You need ai.configure. The MCP Servers menu is hidden from everyone else.
- You need the server's HTTPS address and, if it requires one, a token or key. Use a test server and a test key first.
An MCP server supplies tools the assistant can use. The a2NSoft ERP server is built in and always present. Outside servers are optional.
Steps
Review the built-in tools
- Open AI Assistant > MCP Servers. The tiles show Connected servers, Disconnected, Tool errors, Average latency, Last success and Last failure.
- Open the a2NSoft ERP server and select the Tools tab. Each tool shows its domain, risk, approval policy, calls and errors. Read tools start on and need no confirmation; write tools need confirmation.
- Use the Enabled switch to turn a tool off. The assistant then says it is not allowed to use it.
Add an outside server
- Select Add server. The wizard has eight steps.
- Choose the Server type (Google Drive, Gmail, Microsoft 365, SharePoint, Bank API, Warehouse Scanner, External SQL or Custom API). The tile fills in a name, transport and URL prefix.
- In Connection, enter the Name (up to 80 characters), Transport (Streamable HTTP or HTTP), Endpoint URL (must start with http:// or https://) and a Description.
- In Authentication, choose None, Bearer token or API key header (sent as
X-API-Key), and type the Secret. - Select Save & test. If it connects you see the server name and version. Then Discover tools.
- Switch on only the read tools you need. Tools found on an outside server start off.
- Assign the agents that may use the server, then select Activate.
Set risk and approval
- On the Tools tab, set each tool's Risk: READ_ONLY, LOW_RISK_WRITE, MEDIUM_RISK_WRITE, HIGH_RISK_WRITE or CRITICAL. Set the Approval policy. DISABLED also switches the tool off.
- A tool that changes data can be made riskier, never READ_ONLY, and always asks for confirmation.
Test a tool
- Select Test tool, enter input as JSON such as
{"query": "Test"}, and run it. Only read-only tools can be run here, with your own permissions.
Other tabs
- Use Overview, Resources, Prompts, Agents, Logs and Settings. In Settings, type a new secret to replace the old one; blank keeps the old.
- Connect / Disconnect, Test and Delete are in the server row.
What happens next
- An activated server shows Connected, and its enabled read tools appear in chat as a block titled '<server> · <tool>'.
- The activity log shows the server column for each call.
- The secret is sealed. The screen only learns that a secret exists.
Good to know
- 'The endpoint must be an http(s) URL.' 'A server needs a name.' 'Give the server's address.'
- 'The sse transport is not supported yet; use Streamable HTTP.' WebSocket is not supported and stdio is not allowed.
- A failed test shows an error such as HTTP status or AUTH_REQUIRED, and the Logs tab keeps it.
- 'Only read-only tools can be run from here; a write goes through a chat and a confirmation.'
- 'A tool that changes data cannot be classified as read-only.' 'A tool that changes data always asks for confirmation.'
- Outside write tools are refused: '<tool> on <server> changes data and needs an approval flow that external tools do not have yet.'
- The built-in server cannot be deleted: 'The a2NSoft ERP server can be restricted tool by tool, not deleted.' Deleting an outside server (confirm 'Delete this server and its tool registry?') removes it from every agent.
- Important: the server calls whatever address you enter, including internal addresses. Only add servers you trust.
- An agent with no servers ticked uses every enabled outside server. Tick servers on an agent to restrict it.
- a2NSoft's own MCP endpoint is available for outside tools to read your ERP: it lists read tools and answers with the signed-in user's permissions. It does not check the tool switches or the never-send list, so treat it as a technical interface for administrators.
- Two administrators editing one server: the last save wins.