Connect an External MCP Server
This guide covers connecting an external MCP server to Chainabit. To expose Chainabit as an MCP server instead, see the Chainabit MCP server guide; the NEXUS local MCP server is a separate product.
Availability
Connecting an external MCP server requires the MCP connector to be enabled for your deployment and your account to have access. If it is unavailable, stop at the availability response; do not attempt to change platform configuration.
Setup
When the connector is available:
- Discover tools as a stateless preview; this creates no connector instance.
- Create a connector instance with the server URL, transport, and authentication type.
- Store credentials if that authentication type requires them; skip this step for
none. - Sync the server's tools to the instance.
- Review and approve each discovered tool before use. Every discovered tool requires approval by default.
Transport
Choose Streamable HTTP (streamable-http), the default, or legacy SSE (sse) transport for the external server. Both require a public HTTPS endpoint; a local stdio server is not a remote endpoint Chainabit can connect to. Detailed wire examples and limits are withheld until an enabled deployment can be exercised.
Authentication types
A connector instance selects one authentication type: none, api_key, bearer_token, basic_auth, or custom. Credentials, when needed, belong in the credential vault, never in the instance's public configuration, and are never returned in responses. The exact per-type request and outbound-header examples are withheld until an enabled deployment can be exercised end to end.
An OAuth-protected MCP server may accept a bearer token obtained separately. A built-in OAuth authorization path is not documented as available until it can be exercised against the running API.
Available Tools
When available, this connector discovers tools dynamically from an external MCP server. Sync after creating the connector instance and storing credentials if the authentication type requires them.
Examples
Copyable connection examples are withheld until the MCP connector is enabled and the full flow can be verified against the running API. See Availability before attempting a connection.
Security
When external MCP connections are available, servers must be reachable over public HTTPS. Private, loopback, link-local, and metadata addresses are rejected, and redirects are not followed. Treat tool output as untrusted input. Every discovered tool requires approval by default.
Keep secrets in the credential vault, not in a connector instance's public configuration.
Troubleshooting
If the MCP connector is unavailable for your deployment or account, the connection flow cannot continue. Do not retry with different credentials or change platform configuration to work around availability.