Skip to content

MCP and tool allowlists

openagentix connects to tools through the Model Context Protocol with the official TypeScript SDK. MCP servers are configured once; agents get access through grants in agents.md.

[
{
"name": "github",
"transport": "stdio",
"command": "/opt/mcp/github-mcp-server",
"args": ["stdio"],
"envSecrets": { "GITHUB_TOKEN": "github.token" },
"timeoutMs": 30000,
"maxResultBytes": 262144
},
{
"name": "tickets",
"transport": "streamable-http",
"url": "https://mcp.internal.example/tickets",
"headerSecrets": { "authorization": "tickets.auth" }
}
]
FieldMeaningDefault
transportstdio or streamable-http
command, argsfor stdio: a pinned binary; never npx <package>@latest
env, envSecretsenvironment for the server; only these plus a safe base set are passed
url, headers, headerSecretsfor streamable-http
timeoutMsper call30000
maxResultByteslarger results are truncated with a marker262144
clearancehighest data classification the server may receive

The agent’s tools list is its allowlist. The model is shown only the intersection of granted tools and the tools the server offers, named server__tool. Every call is decided by the audit gate before it reaches the server; results are ok, denied or approval_required.

tools:
- server: github
tool: create_pull_request
approval: required
args:
owner: { type: string, const: my-org }
repo: { type: string, enum: [api, web] }
base: { type: string, const: main }

tool_timeout, tool_failed, mcp_unknown_server, mcp_unavailable.

openagentix can expose an MCP server named openagentix-gate that offers only an agent’s granted tools and runs each call through the gate, audit and cost tracking. External harnesses are pointed at this server instead of the real tools; see External harnesses.

Roadmap MCP servers are registered per tenant, either as a remote endpoint or as a container that the platform starts. Each agent gets a tool allowlist and argument constraints; a catalog with review states decides which servers a tenant may register at all. Your own servers are first-class: the same gate, audit and cost tracking apply as to any other tool.