Integrations
If it has an API, a database or an MCP server, it is in scope
There is no integration catalogue to wait for. Caterfli reads whatever you point it at and normalises it into the same shape as everything else.
Model Context Protocol
MCP server
Point at an MCP endpoint and its tools are imported with their schemas intact. Streamable HTTP and SSE transports.
- ✓ Tools, arguments and descriptions preserved
- ✓ Streamable HTTP and SSE
- ✓ Re-sync when the server changes
OpenAPI, or described by hand
REST API
Give it an OpenAPI document and every operation becomes a tool. No document? Describe the endpoints and they compile the same way.
- ✓ OpenAPI 3.x parsing
- ✓ API key, bearer and basic auth
- ✓ Per-tool timeouts and rate limits
PostgreSQL and MySQL
Database
Tables, columns, types and foreign keys are read directly, and the relationships between them become part of what the agent understands.
- ✓ Schema and relationships discovered
- ✓ Row limits enforced per query
- ✓ Read-only unless you say otherwise
The platform itself
Built-in toolkit
Dates, arithmetic, reference codes and email — the things a language model gets confidently wrong, done properly, with nothing to connect.
- ✓ No credential, no endpoint, no expiry
- ✓ Email recipients allow-listed, empty by default
- ✓ Arithmetic that is actually correct
Your agents, to each other
Agent delegation
Any agent can be exposed as a tool the others call, so specialists stay specialists instead of one agent holding every capability.
- ✓ A delegated run is a full run of its own
- ✓ It cannot borrow reach it does not have
- ✓ Depth limited; loops cannot form
Something else?
Tell us what you would connect first. We will say honestly whether it fits today or is on the list.
Ask usOne registry
Everything becomes the same thing
An MCP tool, a REST endpoint, an OpenAPI operation and a SQL table arrive as one kind of object: a described capability with an input schema, an operation type and a risk level. Policy is written once and applies to all of them.
-
1
Discovered
The connector reports what exists — an endpoint, a table, an MCP tool.
-
2
Described
A name, a summary and an input schema the platform can validate against.
-
3
Classified
An operation type — read, create, update, delete, execute, export, analytics.
-
4
Rated
A risk level, which is what decides whether a person has to say yes.
discovery · MySQL
ready- list_customers read
- sales_report analytics
- create_order create
- update_order update
- delete_customer delete Approval
The operation type is not cosmetic — it is what the policy engine reads when it decides whether this call needs a person.
Agent delegation
Agents that hand work over
The alternative to delegation is one agent holding every tool in the business, which is both worse at its job and far more dangerous when it is wrong. Instead a generalist passes the billing question to the agent that knows billing.
The hop is a full run in its own right: its own trace, its own policy checks, its own approvals. An agent cannot reach through a colleague to touch something it was not allowed to touch directly.
delegation
“refund order 4471 — customer was double charged”
- its own execution, its own trace
- its own approval gates
- cannot reach what it could not reach alone
The delegated run is checked from scratch. Being asked by a colleague is not a permission.
Where people talk to it
The way in matters less than the checks behind it
Web chat, Telegram, Slack and WhatsApp all reach the same runtime under the same policy set. A sender on a channel carries nobody’s permissions until you put them on the allow-list, which starts empty.
-
Web chat
With live reasoning
-
Telegram
Bot API
-
Slack
Slash commands
-
WhatsApp
Cloud API
-
REST API
Your own front end
-
Webhooks
Signed, replay-proof
Point it at the first thing
Connect one system and read the agent Caterfli writes from it. There is a demo connection too, if you would rather look before you wire anything up.