You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 03dffb4
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: apps/docs/content/docs/agents/mcp.mdx
+31-4Lines changed: 31 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -117,16 +117,16 @@ Once MCP servers are configured, their tools become available within your agent
117
117
/>
118
118
</div>
119
119
120
-
4. Select individual tools, or choose **Use all N tools**to add every tool from that server
120
+
4. Select individual tools, or choose **Configure operations access**for a dynamic server attachment
121
121
5. The agent can now access these tools during execution
122
122
123
123
<Callouttype="info">
124
124
If you haven't configured a server yet, click **Add MCP Server** at the top of the dropdown to open the setup modal without leaving the block.
125
125
</Callout>
126
126
127
-
## Standalone MCP Tool Block
127
+
## Standalone MCP Block
128
128
129
-
For more granular control, you can use the dedicated MCP Tool block to execute specific MCP tools:
129
+
Use the MCP block to discover operations or run one operation with explicit inputs:
130
130
131
131
<divclassName="flex justify-center">
132
132
<Image
@@ -138,7 +138,34 @@ For more granular control, you can use the dedicated MCP Tool block to execute s
138
138
/>
139
139
</div>
140
140
141
-
The MCP Tool block runs one configured tool with parameters you set explicitly, and its output is readable by later blocks like any other.
141
+
Choose an **Action**:
142
+
143
+
-**List operations** discovers authorized operation names, descriptions, and input schemas without executing provider operations. Filter by name or description, set a page size from 1 to 100, and pass `nextCursor` into the next request while `hasMore` is true. An authorized list can be empty.
144
+
-**Run operation** executes one exact operation name. Configured operations keep their generated argument fields. For an operation name resolved at runtime, supply a JSON arguments object; Sim validates it against the operation's discovered schema before execution.
145
+
146
+
**MCP Server** takes one shared-server ID or managed-connection ID. Sim resolves a managed connection's parent server internally and verifies workspace and credential access. Both actions accept the same ID; List operations returns that ID as `serverId`, alongside the discovered `operations` and pagination metadata.
147
+
148
+
The standalone block's Basic fields select a configured connection and discovered operation. Advanced fields accept literal IDs/names or upstream references. A runtime server reference requires JSON arguments. Listing hides the operation and argument fields.
149
+
150
+
### Operations access
151
+
152
+
The **MCP Server (Advanced)** Agent attachment takes a server/connection ID or upstream reference in a plain input. Its **Tool IDs** field accepts exact MCP tool names, such as `search_docs`, entered directly. These are the names returned by List operations, without a Sim server prefix. Neither field uses a server or operation catalog picker.
153
+
154
+
Agent attachments have three access modes:
155
+
156
+
| Mode | Behavior |
157
+
| --- | --- |
158
+
|**Only selected**| Allows only selected exact operation names. An empty selection allows nothing. Newly discovered names stay excluded. |
159
+
|**All except selected**| Denies selected exact names. An empty selection allows everything otherwise permitted. Denied names stay saved if they temporarily disappear. |
160
+
|**All permitted**| Allows every operation available to the authorized credential. |
161
+
162
+
New restricted configurations start with an empty explicit selection. Existing saved workflows retain their prior access through normalization, while current organization and credential authorization still apply.
163
+
164
+
Operation restrictions are saved in workflow state on the Agent attachment. Tool IDs are literal configuration, not upstream references or model arguments. An operation must be available to the resolved, authorized connection and permitted by the saved restriction. The standalone block runs its explicitly specified operation and has no separate access policy.
165
+
166
+
Discovery filters the tools exposed to the Agent. Execution checks the actual server, connection, and saved restriction again before calling the provider. Missing or forbidden operations, unverifiable schemas, malformed arguments, and incorrect connection scopes fail the call. An Agent attachment with no permitted operations fails clearly.
167
+
168
+
Policies match exact, case-sensitive MCP tool names on whichever authorized connection resolves at runtime. They do not inspect operation arguments: allowing a generic `execute_sql` operation does not limit which SQL it can execute.
Agent Skills are reusable packages of instructions that give your AI agents specialized capabilities. Based on the open [Agent Skills](https://agentskills.io) format, skills let you capture domain expertise, workflows, and best practices that agents can load on demand.
9
10
@@ -93,7 +94,7 @@ Tagging a skill loads its full instructions into the conversation, so Sim follow
93
94
94
95
Open any **Agent** block and find the **Skills** dropdown below the tools section. Select the skills you want the agent to have access to.
0 commit comments