Skip to main content
Use a custom MCP server when the tool you need isn’t in the catalog but exposes an MCP endpoint. Your own internal service qualifies too. A connected server behaves like any other integration. You pick which of its tools are active. You grant them agent by agent. Every call is logged.
The server is third-party and unverified. Atako shows you the tools it declares, but can’t vouch for what they do. Connect servers you trust.

Add a server

On the Context storey, open the Integrations cube and click Add an MCP server. The dialog has three steps.
1

Describe the server

Enter a name, the scope (company or personal), and the server URL. Pick the authentication:
2

Test the connection

Atako connects to the server and lists its tools. If it fails, the message says why: URL refused, server unreachable, authentication required or rejected, not an MCP server, or too many tools.
3

Choose the tools

Tick the tools to activate. Nothing is active until you tick it. Each tool is tagged Read or Write, from the hints the server declares. A tool with no hint counts as Write. Change the tag if it’s wrong. Tools the server marks as destructive carry a Destructive label and start unticked. Enable all and Read-only select in bulk.
Click Connect N tools to finish. Then open an agent’s settings and grant the tools you want it to use. Without a grant, the agent can call nothing.

Several connections to one server

The same server can be connected more than once: one token per person, or two accounts on the same service. Give each connection its own name. The agent sees each connection under a short name derived from it.

Tool changes and review

Open Manage on the connection to Resynchronize. Atako reads the server’s tool list again.
  • A tool that is new or whose description or input schema changed is suspended. It stays off until you review it. A banner lists these tools.
  • A tool that disappeared is removed and dropped from every grant.
  • Only an explicit Validate lifts the review. Turning the tool on is not enough.
  • A changed tool is also removed from every agent’s grant. After validating it, grant it again agent by agent, knowing its new description.
This stops a server from silently changing what a tool does, or slipping in new instructions, after you approved it. A suspended tool is withdrawn from agents within about a minute.

Rotate the token

In Manage, enter a new token. Atako tests it against the server before saving.

Limits

Security

  • The token is encrypted on submit and never leaves Atako. It isn’t shown again, not even to you.
  • The agent never talks to the server. It sends an intent to the platform, which checks the grant, calls the server with the token, and returns the result.
  • Atako resolves the server’s address and connects to that exact address, so a hostname can’t be switched to an internal one between the check and the call.
  • The full server URL may contain a secret. Only the people who can manage the connection see it; others see the host only.
  • A personal server follows the personal scope rules: invisible to others, masked in logs.
See also Security and Permissions.