MCP connector · switches on at setup
Any MCP server
EnableableBring your own tools. Any server speaking streamable-HTTP or SSE joins the same gate — your databases, your internal SaaS, your own scripts.
Every tool, and its gate
Three gate modes on every discovered tool
inheritA read-only tool follows the Pie's autonomyinheritfirst-useEvery newly discovered tool asks you the first timefirst-use asks youalwaysPin any tool to ask on every callalways asks
on the chain as mcp:<your-server>.<tool> · parameters hashed, never raw
What it cannot do
- Reach an internal host on the SSRF denylist
- Run a tool whose schema changed, without re-approval
- Put raw parameters on the audit chain — they are hashed
Where the credential lives
The server URL plus its own credential, sealed in the vault. The SSRF denylist applies to every host.
write-only · never in logs · never in our cloud
Pies that use it
Setting it up
Three steps, one leash
- Register the server URL and its credential
- Approve each tool's first use
- Re-approve if the vendor changes a tool's schema
Keep reading
Up to the directory and the gate it all shares — then two more tools on the same leash.
Wire Any MCP server into a workforce with a record
See every connector's honest status alongside the rest, then choose your plan.