> ## Documentation Index
> Fetch the complete documentation index at: https://docs.atako.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a custom MCP server

> Plug any remote MCP server into Atako as an integration, with per-tool control.

Use a custom MCP server when the tool you need isn't in the [catalog](/integrations/overview) but exposes an [MCP](https://modelcontextprotocol.io) endpoint. Your own internal service qualifies too.

A connected server behaves like any other integration. You pick which of its tools are active. You grant them agent by agent. Every call is logged.

<Warning>
  The server is third-party and unverified. Atako shows you the tools it declares, but can't vouch for what they do. Connect servers you trust.
</Warning>

## Add a server

On the Context storey, open the **Integrations** cube and click **Add an MCP server**. The dialog has three steps.

<Steps>
  <Step title="Describe the server">
    Enter a name, the [scope](/guides/integration-scope) (company or personal), and the server URL. Pick the authentication:

    | Mode | When |
    | - | - |
    | **None** | Public server. |
    | **Bearer token** | The server expects `Authorization: Bearer <token>`. |
    | **Custom header** | The server expects a token in another header. Enter the header name and the value. |
  </Step>

  <Step title="Test the connection">
    Atako connects to the server and lists its tools. If it fails, the message says why: URL refused, server unreachable, authentication required or rejected, not an MCP server, or too many tools.
  </Step>

  <Step title="Choose the tools">
    Tick the tools to activate. Nothing is active until you tick it. Each tool is tagged **Read** or **Write**, from the hints the server declares. A tool with no hint counts as **Write**. Change the tag if it's wrong. Tools the server marks as destructive carry a **Destructive** label and start unticked. **Enable all** and **Read-only** select in bulk.
  </Step>
</Steps>

Click **Connect N tools** to finish. Then open an agent's settings and grant the tools you want it to use. Without a grant, the agent can call nothing.

## Several connections to one server

The same server can be connected more than once: one token per person, or two accounts on the same service. Give each connection its own name. The agent sees each connection under a short name derived from it.

## Tool changes and review

Open **Manage** on the connection to **Resynchronize**. Atako reads the server's tool list again.

* A tool that is **new or whose description or input schema changed** is suspended. It stays off until you review it. A banner lists these tools.
* A tool that disappeared is removed and dropped from every grant.
* Only an explicit **Validate** lifts the review. Turning the tool on is not enough.
* A changed tool is also **removed from every agent's grant**. After validating it, grant it again agent by agent, knowing its new description.

This stops a server from silently changing what a tool does, or slipping in new instructions, after you approved it.

A suspended tool is withdrawn from agents within about a minute.

## Rotate the token

In **Manage**, enter a new token. Atako tests it against the server before saving.

## Limits

| Limit | Value |
| - | - |
| URL | Public `https` only. Private, loopback and link-local addresses are refused. No credentials in the URL. Port 443 or 1024 and above. |
| Redirects | Not followed. |
| Connections | 10 MCP connections per company, and 10 personal ones per user. |
| Active tools | 60 per connection. |
| Tool names | Letters, digits, `_`, `.` and `-`, 64 characters max. Other tools are ignored. |
| Tool description | Cleaned and cut at 600 characters. Input schemas are cleaned and capped at 16 KB. |
| Response | Reading stops at 4 MB. What reaches the agent is cut at 256 KB, flagged as truncated. Non-text content is replaced by a placeholder. |
| Time | 10 s to connect, 30 s per call. |
| Authentication | None, Bearer token or custom header. OAuth-protected MCP servers aren't supported yet. |

## Security

* The token is encrypted on submit and never leaves Atako. It isn't shown again, not even to you.
* The agent never talks to the server. It sends an intent to the platform, which checks the grant, calls the server with the token, and returns the result.
* Atako resolves the server's address and connects to that exact address, so a hostname can't be switched to an internal one between the check and the call.
* The full server URL may contain a secret. Only the people who can manage the connection see it; others see the host only.
* A personal server follows the [personal scope rules](/guides/integration-scope): invisible to others, masked in logs.

See also [Security](/integrations/security) and [Permissions](/integrations/permissions).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.