# Connectors (MCP)

A connector gives a Pro model tools from another service, over the Model Context Protocol. Nothing runs without your say-so unless you choose otherwise.

## What is a connector

Many services now publish an MCP server: an address that lists tools a model can call, such as searching an issue tracker, reading a calendar or querying a database. Add one to Nymbot and a [Pro](https://nymbot.ai/docs/models/#pro) reply can use those tools while it answers.

The Nymbot worker is what talks to the server, so the server sees the worker rather than your device. What a tool returns is passed to the model marked as outside data, and the model is told never to follow instructions inside it.

Connectors need a Pro model pinned. Standard and free replies do not use them.

## Adding one

Open **Connectors** from the menu or the toolbar chip and add one with a name and the server's address. The address has to be `https` and publicly reachable; a local or private address is refused, because the worker could not reach it. For sign-in, choose no authentication, a bearer token, or a custom header. Keep credentials in those fields rather than in the address.

Nymbot connects to the server and lists the tools it offers. Uncheck any tool you do not want Nymbot to have. Each tool also shows what the server says about it: that it only reads, or that it can delete things.

A connector you add is available to every chat. Pick which ones a chat uses from the chip, up to three at a time.

## Approving a tool call

When the model wants to use a tool, the reply pauses and shows a card: which connector, which tool, and exactly what it would send. You choose:

- **Allow once** runs that one call, and the reply carries on from where it stopped.
- **Always allow this tool** runs it and stops asking about that tool on that connector from now on.
- **Deny** runs nothing. The reply carries on without it.

A card left too long expires. Ask again and Nymbot starts fresh. If carrying on could go past the chat's [spending cap](https://nymbot.ai/docs/credits/#caps), it stops instead.

## Letting a tool run without asking

In the connector's settings, each tool has an **Always allow** switch, and **Always allow all tools** covers the whole connector. Tools you allow this way run without a card.

> **Always asks**
>
> A tool the server marks as able to change or delete things always asks, whatever you have allowed. It cannot be allowed ahead of time, and its card says why.

## Where the secrets live

A connector's token, header value and address are kept on your devices. They sync between your devices inside your end-to-end encrypted settings, sealed with your key, so the server stores only a copy it cannot read. That also means a chat that uses a connector works on every device you sign in on, without setting it up again.

The secret travels to the worker with each request that uses the connector, because the worker is what calls the server. It is not stored there. With [identity encryption](https://nymbot.ai/docs/identity/#encryption-at-rest) on, it is encrypted on the device too. Removing a connector removes it, and its secrets, from your other devices as well.
