Connecting an MCP server
A URL and a token. The server describes the rest — except how dangerous it is.
An MCP server describes its own capabilities, so connecting one imports every tool it exposes along with the argument schemas it declares. It is the least configuration of any connection: a URL, and a token if the server wants one.
What you need
- •Server URL — the MCP endpoint, usually ending in
/mcp. - •Bearer token — if the server is authenticated. Leave it blank if not.
- •Additional headers — anything else the server expects, such as a tenant or workspace id.
Streamable HTTP transport only. A local stdio server cannot be connected — that would mean running your process on our infrastructure.
How risk gets decided
MCP describes what a tool takes and what it returns. It does not describe how dangerous the tool is, which is the thing the platform most needs to know.
So Caterfli infers an operation type from each tool's name and any hints the server provides, and errs towards caution: an unrecognised verb is treated as an action rather than a read. An action inherits a higher risk level, which means an approval rule can catch it.
Expect the consequence. After connecting a server you may find tools marked riskier than they really are. Correct them on the tools page. A tool the platform guessed wrong in the safe direction stops for a person; guessed wrong the other way, it would not.