Connect a Tool
Extend what your agents can do: connect an external system as a remote MCP server, or write a custom Python tool, both shared across your organization.
Praxis agents come with a broad set of built-in tools, but every team eventually needs one Praxis does not ship. There are two ways to add your own. Connect an external system as a remote MCP server, and Praxis discovers the tools it exposes so your agents can call them. Or write a custom Python tool for a small piece of logic that does not warrant a whole service. MCP (Model Context Protocol) is the standard connection layer that lets an agent drive an outside system as a tool.
Cloud (AWS, GCP, Azure), Kubernetes, New Relic, and the Facets control plane are already built in. You switch them on per agent, and they draw on the integrations your organization connects once, so you do not add them as MCP servers. See Build your own agent.
Connect a remote MCP server
You can connect a server in chat or from Settings.
In a chat session, ask an agent to connect a server at its URL, for example connect our GitHub MCP server at https://mcp.example.com/sse. Praxis tests the endpoint first. If it needs authentication, the agent asks for the credentials through a secure prompt instead of taking them inline in the conversation. Once the endpoint responds as a valid MCP server, Praxis saves it and reports the tools it found.
From Settings, open MCP Servers and choose Add MCP Server:
- Give the server a unique name, a display name, and pick its transport, either Server-Sent Events (SSE) or HTTP.
- Enter the server URL. For any header that carries a secret, reference a stored credential with
${credential:name}rather than pasting the value. - Choose Test Connection. Praxis connects, confirms the endpoint completes the MCP handshake, and lists the tools it exposes. You cannot save until this test passes, and changing the URL, transport, or headers makes you test again.
- Save the server.
Both transports are remote: Praxis connects out to a URL you control and never runs a local server as a subprocess (see how connecting a tool stays safe). A connected server belongs to your organization. Everyone in your org can attach it to their agents, and the person who created it can edit or remove it.
Reference credentials securely
You never put a secret directly into a connection or a chat message. When a server needs authentication, reference the secret in a header as ${credential:name}, and Praxis substitutes the real value server-side each time a tool runs. The value itself is entered once through a secure prompt, stored encrypted, and never shown back to you, to the agent, or in logs.
Credentials are their own managed objects. You review them, rotate a stored value, or remove one under Settings > Credentials, where each is marked either personal to you or shared with your organization. Praxis blocks deleting a credential that a connected server still references, so a live connection does not lose its secret by accident. For how credentials are encrypted and injected, see How Praxis works.
Attach and manage a server
Connecting a server makes it available; attaching it to an agent is what puts its tools in that agent's hands. Attach only the servers an agent's job needs, so each agent carries a focused tool set, and enable or disable an attached server without detaching it. Attachments are configured per agent, alongside the rest of an agent's setup in Build your own agent.
To change a server, edit it. Because a new URL or header can alter what the server exposes, Praxis makes you re-test the connection before it saves. You can also list, inspect, or re-test your servers by asking Praxis in chat. To remove a server, delete it from MCP Servers, confirming by typing its name.
Deleting a server cannot be undone. It removes the server for everyone in your organization and detaches it from every agent it was attached to, across all users. Check what depends on it first.
How connecting a tool stays safe
Connecting a tool is guarded on three fronts:
- Remote servers only. Praxis connects out to remote HTTP(S) endpoints and never launches a local server as a subprocess, a path that could be used to run arbitrary commands on the server.
- URL screening. Praxis rejects a server URL that points at internal or private infrastructure: localhost, cloud metadata addresses, private IP ranges, and bare single-label hostnames. This stops a connection from being turned into a way to reach inside private networks.
- Encrypted credentials. Secrets are referenced by placeholder, stored encrypted, and resolved only server-side at run time, never echoed back.
Every tool call also runs server-side under your organization's identity and is audited. For that shared model, see How Praxis works.
Write a custom Python tool
When you need a small piece of custom logic rather than a whole external service, write a custom tool: a Python function that becomes a native agent tool, indistinguishable from a built-in one. You build it by asking Praxis in chat, which writes it, tests it in an isolated sandbox, and publishes it for your agents to attach.
Custom tools have their own home. See Custom Tools for how to build, secure, and manage them.
Related
- Custom Tools - Turn a Python function into a native agent tool
- Build your own agent - Attach connected tools and set what an agent can reach
- How Praxis works - The server-side, audited safety model behind every tool call
- Skills - Reusable instructions your agents load on demand