# MCP

Give an agent access to tools on an external MCP server. Review required fields, credential setup and how this connector works in Zild.

Source: https://zild.ai/en-US/docs/apps/zild-admin/connector-mcp

Give an agent access to tools on an external MCP server.

## Where to configure

Open Zild Admin → Integrations → Connectors, find the provider and use Configure or Edit. Enter the data from this guide, enable the connector for the workflow and save.

## Required fields

These requirements are the data needed by the workflow using the connector. Generic saving may accept empty fields that are only required when an operation runs. Saving does not confirm that the provider accepts the credential.



<table class="api-params"><thead><tr><th>Field</th><th>Workflow requirement</th></tr></thead><tbody><tr><td><code>Name</code></td><td>Connector name.</td></tr><tr><td><code>Url</code></td><td>Absolute HTTPS endpoint, without embedded credentials or a # fragment.</td></tr><tr><td><code>McpSettings</code></td><td>Transport: StreamableHttp or Sse; Authentication: None, Bearer or ApiKeyHeader; TimeoutSeconds from 1 to 300 (default 60).</td></tr><tr><td><code>ApiKey</code></td><td>Required for Bearer or ApiKeyHeader in the form and when connecting to the server; omitted for None.</td></tr><tr><td><code>McpSettings.ApiKeyHeaderName</code></td><td>Required for ApiKeyHeader; use an allowed header name, such as X-API-Key.</td></tr></tbody></table>



## How to obtain credentials

- Obtain the endpoint and credential from the service hosting the MCP server. There is no universal MCP key.
- Choose None for an unauthenticated server, Bearer for a token, or ApiKeyHeader for a key in a custom header.
- Paste only the credential into ApiKey, without the Bearer prefix. For ApiKeyHeader, also enter the header name required by the provider.
- Associate the connector with the agent, discover its tools and explicitly select the allowed tools.

## How it works in Zild

The API validates Name, Url and McpSettings. The connector must belong to the workspace and cannot be a global default. Reserved headers (such as Authorization, Host and Content-Type) and Mcp- prefixes are rejected in ApiKeyHeader mode. The implementation supports static credentials without an interactive OAuth flow. Discovery does not authorize tools; an empty AllowedTools list grants none.

## How to verify the configuration

After saving, use the matching workflow (query, agent, call or processing) to verify access. If it fails, check the credential, permissions and selected provider resource. For limited or legacy types, confirm availability with your administrator before use.

When editing, Zild displays protected credentials as asterisks. Preserve the masked value to keep the current credential or paste a new credential to replace it.

## Official documentation

- [MCP: authorization specification](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)

[Back to Connectors](/en-US/docs/apps/zild-admin/integration)
