Skip to content
Public beta preview — you're seeing the sneak peek

Tools & MCP

read as .md

Agents get capabilities from MCP servers. The Console shows this on two surfaces: each agent’s Tools tab, and the workspace-level MCP Registries section.

Open an agent → Tools to see where its capabilities come from:

  • A workspace agent draws on the MCP servers enabled for its workspace — the header links to Manage registries. The full per-tool listing here is marked coming soon.
  • A personal agent’s servers come from its own deployed configuration — the mcpServers in its guuey.json (see Agents as code). The workspace registry is workspace-only by design.

If the agent’s live deployment declares an MCP server with credential: "oauth", a Connected accounts panel appears per server: how many users have connected, how many granted this agent, the server’s issuer, the last authorize, and any recent refresh error.

The model to know: your users sign in to those services with their own accounts. Guuey holds the tokens — your agent never sees them — and each connection belongs to the user, who manages it inside the app under Settings → Connected services. When you run guuey mcp connect yourself, the browser dance lands back on this tab with a confirmation notice. How the broker works end to end is in MCP proxy & credentials.

Pre-registered client. Some authorization servers cannot register clients on their own: no dynamic client registration and no client-ID metadata documents (Google, GitHub and similar). Each server’s panel has a Pre-registered client section for them. Register an OAuth client with the provider using the Redirect URI to register shown there, then paste its client ID and secret and save; leave the secret empty for a public client. The secret is sealed on save and never shown again, and saving replaces the client ID and secret together. Guuey uses your client only when the provider cannot register one for Guuey; without one, a connection attempt returns with client_registration_unavailable and this tab shows a notice saying so. If the agent’s live declaration of that server changes, the section flags the saved client as saved for the old declaration; save it again to re-pin it.

For servers that keep per-user state, a State panel lets you inspect that server’s key-value store — the same primitive described in State & memory. In environments where durable state hasn’t been enabled yet, the section carries a plain warning instead: state is ephemeral there, and writes do not survive pod restarts.

The sidebar’s MCP Registries section has three tabs. It is workspace-scoped: in personal scope it explains that registries are a team-workspace feature and offers to create one.

The workspace’s server catalog — which MCP servers are enabled for the workspace’s agents. Members see the list read-only; workspace admins can Add Server and Pause / Resume / Remove entries.

Click a server for its detail page: the server’s tools (with schemas), and its State panel. Test-invoke, a consent log, sync settings, and version pinning show as visible coming-soon stubs.

The workspace’s own MCP servers running on Guuey — the ones you shipped with guuey mcp deploy. This view reads the same data as guuey mcp list / guuey mcp status:

  • Delete is live from the Console, and fail-closed: if agents still hold grants on the server, the delete stops and asks you to confirm against the named list — the same flow the CLI walks.
  • Resize has no console button on purpose — it’s a full redeploy from your local source, so each card shows you the CLI command instead of a control that couldn’t do the job.

The workspace’s MCP hosting subscription — checkout, total hosted units, and the first-month credit line. If a guuey mcp deploy is refused because hosting isn’t paid for, the refusal points at exactly this page. Agent plans are separate and per app — see Billing & workspaces.