Docs › Connectors
Connectors (MCP servers)
Give the agent tools from other systems (issue trackers, databases, internal APIs) through the Model Context Protocol.
A connector is an MCP server. It gives the agent tools beyond your codebase: reading an issue tracker, querying a database, calling an internal API. Connectors are for the *agent*; plugins are for the editor.
Adding one from the list
Open the + menu under the composer, choose Connectors, then Add a connector. Each entry shows the exact command it will run, or the address it will call, before anything is written. Some need a credential in your environment; the list names the variable and AstraCode never stores the value.
Adding one by hand
Anything not on the list goes in the astracode.mcp.servers setting. Each entry has an id and then either a command to run or a url to call. An entry with both, with neither, or with an id already taken is skipped, and the reason appears in the log.
Remote servers sign you in
A server reached over url uses OAuth: the first call comes back unauthorised, AstraCode discovers where to authenticate, and a browser opens for you to approve. The token is stored for you; you are not asked to paste one.
While that browser sign-in is open, the editor shows a notification naming the service, with Cancel. If it is not finished within ten minutes, or it fails, the editor tells you why and offers Try again; until then that server's tools are not available to the agent.
Using them
Connector tools appear to the agent as mcp__<server>__<tool>. They always ask for approval before running, in every mode except Bypass. Switch individual connectors on and off from the + menu under the composer. The row appears once you have at least one.
Servers your organisation offers
An admin can publish connectors for the team. These are offered, never installed silently: you see the exact command and nothing runs until you accept.
Your approval is bound to what the server actually runs, not to its name. If an admin changes the command, the arguments or the environment, it reads as a new server that has never been approved and you are asked again. Approval is per machine and is not synced.
A shared connector is a command line written by an admin and run on your machine. Everything above follows from taking that seriously.
Limits
Output from a connector is treated as untrusted and marked as such before the model sees it, because it arrives from software you installed but did not write. There is no open marketplace: the built-in list holds servers published by the vendor of the thing they connect to, and anything else is added by writing its entry in settings.
All documentation
Get started
Agent
- Agent overview
- Approvals and permissions
- Plan mode
- What the agent can do
- Running commands
- Browser tools
- Checkpoints and undo
- Infrastructure as code
- Running several agents at once