MCP Server Auth
Custom MCP server
First create the custom server by entering its name and URL. Then open it for editing: additional fields and authorization options appear after the first save. In the authorization section, choose one option:
- No Authorization — for an open or internal server without a secret;
- Access Token — the cabinet sends
Authorization: Bearer <token>, so enter only the value in the token field; - Additional Headers — for
X-API-Key,Authorization: Basic ..., and custom schemes; - MCP OAuth — standard OAuth authorization for a remote MCP server.

When a saved token should not be changed, an empty field preserves the previous secret only when the form explicitly says so. For additional headers, fill both the name and value of every pair.
Ready-made MCP server
A server installed from the catalog shows only the methods provided by its developer. The Manual Setup tab can contain one token or a set of header fields. Complete the displayed fields and click Save.
On the MCP OAuth tab, click the connection button and finish authorization in the external service.

User authorization in an external MCP
Some MCP servers require not only project authorization, but also separate authorization of an external user or lead. In this case, an agent tool can work only after the required user connects their account in the external service.
In the MCP server list, "Per lead" means access is granted to specific users rather than through one shared project token. For a project connection, the cabinet shows the related project, group, channel, account, workspace, or external ID when the MCP server provides it.
If authorization expired or the external service rejected the token, reconnect the account through OAuth or update the manual access data. Do not paste secrets into dialog messages: tokens and custom headers must be entered only in the MCP server authorization form.
Access validation
After saving a token or OAuth connection, check its status. A successful check means the MCP server accepted the credentials. For an error or unknown state, open the message, verify the token, header values, and external-service permissions, then validate again.
Apply a manual token and headers with "Save". Then run connection validation.
If the agent cannot call an MCP tool, first check whether this server is selected for the agent, then check project authorization or user authorization status, and only after that check the event logs.
If OAuth fails
- check that the authorization window is not blocked by the browser;
- check the server URL;
- check that the server supports MCP OAuth;
- repeat authorization;
- check the error text.
Removing an MCP server
- deleting the server is dangerous and requires confirmation;
- if the server is used by agents, their tools will stop working;
- first check the agents where it is selected.
MCP servers in settings
- project settings page
- Settings item in the side menu