MCP servers¶
Fadenstack connects to MCP servers on behalf of every chat and agent. Register a server once, and everyone who is allowed can use its tools.
How Fadenstack uses an MCP server¶
- Registered by IT. An administrator registers the server in the console, under Extensions → MCP Hub. Fadenstack connects over Streamable HTTP, SSE or stdio.
- Credentials stay on the server. Headers (such as an API key) and environment variables are stored encrypted. After saving, the console shows only their names. They are shared by everyone who uses the server's tools, so register a service account, not a person's key.
- Tool names. Each tool appears as
mcp.<prefix>.<tool>, with a prefix chosen when the server is registered. - Off until wanted. In a chat, a server's tools are off until the user switches them on in the tools panel, names one in the message, or the model finds one that fits the question. An administrator can switch a tool off for everyone.
- Agents. An agent's version says which server tools it may use. See Agents on the server.
- Timeouts. Each server has a timeout per call, 60 seconds unless the administrator sets another, between 5 and 600.
Personal data¶
Each registered server has a privacy setting:
| Setting | The tool gets |
|---|---|
| Redact (the default) | Placeholders instead of personal data |
| Allow | The real values |
| Block | Nothing: a call that contains personal data is refused |
See Personal data.
Tool classes¶
Like every tool, an MCP tool has a class: read, write, destructive, or unknown. An MCP server's own hints (readOnlyHint, destructiveHint) count only if an administrator's rule says to trust them. Otherwise the tool is unknown, and in the default mode the user is asked before it runs. See Tools and approvals.
Next¶
Build an MCP server for a system your organisation runs.