Model Context Protocol

Connect any data source via MCP

Model Context Protocol is the open standard for connecting AI agents to external tools and data. Add a server to your workspace, pick which of its tools are allowed, and they behave like every other tool here — approval-gated, audited, assignable per agent.

  • €5 welcome credit
  • EU AI Act & GDPR by design
  • No credit card

01 — Protocol

What is Model Context Protocol?

MCP is an open protocol created by Anthropic that defines a standard way for AI models to connect to external data sources and tools. Instead of building custom integrations for every service, you expose a compliant MCP server once — and any agent that understands the spec can use it immediately.

AgentWorks adds the governance layer around it. A server belongs to your workspace, an admin decides which of its tools are enabled, and you assign those tools to the agents that need them. Every call then runs through the same approval gate and audit trail as a built-in tool.

02 — Connectors

Four ways to bring your data to an agent

From managed databases to a fully custom endpoint you build yourself — every connector speaks the same open protocol, and every one runs behind the same governance layer.

Database MCP servers

Let an agent answer questions from your operational data without handing anyone a connection string — the credentials stay with the server, and you decide which of its queries are enabled.

File & document servers

Reach a document library that never made it into a knowledge base. You enable the read tools you want, and assign them only to the agents that need them.

Internal API servers

Put your own ERP, ticketing or booking system in front of an agent. Enable the operations you are comfortable with; every call is approval-gated and logged.

Custom MCP servers

Build your own server for a proprietary source using the open spec. AgentWorks connects to any compliant endpoint and discovers its tools automatically.

Add a server

Add a server, then choose what it may do

  • Discovery lists what the server offers; an admin enables tools one by one
  • OAuth with PKCE and dynamic client registration — no manual credential swap
  • Enabled tools appear namespaced in the workspace, alongside first-party tools
  • Test the connection before you trust it, and revoke a server in one step

Point AgentWorks at an MCP server and it registers itself: the platform discovers the tools the server offers and lists them for an admin. Nothing is live until someone ticks it. Servers that need a sign-in handle it with standard OAuth — including dynamic client registration, so you are not hand-copying client IDs.

Governance & audit

The same guardrails as a first-party tool

  • Least privilege — an agent gets only the enabled tools you assign to it
  • Approval gates apply: reversible writes ask once, irreversible actions ask every time
  • Every call is written to the append-only audit trail before it runs
  • Tenant identity comes from the request, never from the model — no cross-workspace reach

An MCP tool is not a side door. It runs through the same dispatcher as everything else, which means the same approval gate, the same risk class, the same audit row — and the same rule that a tool never learns which workspace it is running for.

Your data never flows directly from source to model.

Every MCP call is proxied through the platform, logged, and limited to the tools an admin enabled and assigned — so what a model sees is always something someone chose to allow, never a raw pipe to your systems.

Start free — claim your €5 credit, no credit card

Connect your first governed MCP server today

Bring any database, file store, or internal API to your agents — scoped, logged, and owned from the first call.

Prefer the wider view? AI tools overview