Either way, the tool must also be selected in the session’s
tools. Nothing reaches the agent unless you select it.
Per-session MCP server with a per-user token
1
Allow users to attach an MCP server
Add
mcp_servers:attach to the permissions you grant during onboarding.2
Attach and select the server when creating the session
3
Rotate the token on every message
beforeForwardMessage runs on your server before each message the browser sends. Return a fresh token and any per-message context:4
Authorize every call in your MCP server
Validate the token and derive the tenant and user from it. Never trust a tenant or record id the model supplies without checking it belongs to that user.
modelContext is visible to the model and in the session’s audit events, so never put secrets in it.
To require human approval before a tool runs, set requireApproval: true on the server, or list specific tool names. See Approvals & questions.
OpenAPI Integration
If your product already has an HTTP API, publish a focused OpenAPI 3.0 or 3.1 document with only the operations the agent may use. Preview it, choose the operations, and install the exact revision you reviewed:Reachability
MCP server URLs and OpenAPI documents must be public HTTPS URLs the OpenGeni deployment can reach. For local development, expose your server with a tunnel such ascloudflared tunnel --url http://localhost:4101 or ngrok http 4101.
Keep the tool surface small
Tool schemas cost prompt tokens on every turn. UseallowedTools to expose only what the use case needs, and keep writes approval-gated unless you want the agent to act on its own.