Skip to main content
The agent reaches your product through tools you expose. OpenGeni calls them on the agent’s behalf; your API authorizes every call. There are two main ways to do it: Either way, the tool must also be selected in the session’s tools. Nothing reaches the agent unless you select it.

Per-session MCP server with a per-user token

1

Allow users to attach an MCP server

Add mcp_servers:attach to the permissions you grant during onboarding.
2

Attach and select the server when creating the session

Header values are encrypted at rest and never returned in responses or events.
3

Rotate the token on every message

beforeForwardMessage runs on your server before each message the browser sends. Return a fresh token and any per-message context:
OpenGeni applies the update atomically as the message is accepted. The browser can never send credential updates itself.
4

Authorize every call in your MCP server

Validate the token and derive the tenant and user from it. Never trust a tenant or record id the model supplies without checking it belongs to that user.
Make the token outlive one turn: agents can work for many minutes. modelContext is visible to the model and in the session’s audit events, so never put secrets in it. To require human approval before a tool runs, set requireApproval: true on the server, or list specific tool names. See Approvals & questions.

OpenAPI Integration

If your product already has an HTTP API, publish a focused OpenAPI 3.0 or 3.1 document with only the operations the agent may use. Preview it, choose the operations, and install the exact revision you reviewed:
Integrations belong to a workspace, so every session in that workspace can select them. They are the right fit for background agents, which cannot carry a per-session MCP server. GraphQL endpoints and workspace-wide MCP connections are also supported.

Reachability

MCP server URLs and OpenAPI documents must be public HTTPS URLs the OpenGeni deployment can reach. For local development, expose your server with a tunnel such as cloudflared tunnel --url http://localhost:4101 or ngrok http 4101.

Keep the tool surface small

Tool schemas cost prompt tokens on every turn. Use allowedTools to expose only what the use case needs, and keep writes approval-gated unless you want the agent to act on its own.
Using a coding agent? The opengeni-client skill covers this.